« Volver al listado

CVE-2013-1085

Estado: ModificadaAlta (9.3)—

Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1085",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-29T16:09:05.767",
  "references": [
    {
      "url": "http://www.novell.com/support/kb/doc.php?id=7011935",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-13-036/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=777352",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/support/kb/doc.php?id=7011935",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-13-036/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=777352",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en pila en el nim: protocolo de manejo en Novell GroupWise Messenger v2.04 y anteriores, y Novell Messenger v2.1.x y v2.2.2, que permite a atacantes remotos ejecutar código arbitrario a través de un comando de importación que contiene una cadena larga en el parámetro de nombre de archivo."
    }
  ],
  "lastModified": "2026-06-16T23:50:49.427",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:groupwise_messenger:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB509022-E2BC-4C23-BB84-BF61CA1AA5B5",
              "versionEndIncluding": "2.0.4"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise_messenger:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDFEE4D7-3B43-4253-AF31-6A3A3930A54F"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise_messenger:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A74668F2-8DFE-4E24-9BB7-91D1F8452C07"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise_messenger:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "142A3EF7-C31E-4CB0-A023-D4DBE081EC05"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:messenger:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4413424-8A43-4496-AB8E-10A7B00FD701",
              "versionEndIncluding": "2.1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:messenger:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC2D18DF-21C7-48FC-AE99-CAC8067303A1",
              "versionEndIncluding": "2.2.1"
            },
            {
              "criteria": "cpe:2.3:a:novell:messenger:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B9C5C89-0E67-4C0E-91BB-5B0159022939"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "Per http://www.novell.com/support/kb/doc.php?id=7011935\r\n\r\nAffected versions:\r\nNovell Messenger 2.2.1 (and earlier)\r\nNovell Messenger 2.1 (and earlier)\r\nGroupWise Messenger 2.04 (and earlier)",
  "sourceIdentifier": "cve@mitre.org"
}