Novell Messenger Server < 2.2.1 Memory Information Disclosure

medium Nessus Network Monitor Plugin ID 6057

Synopsis

The remote host has an instant messaging server product installed that is affected by an information disclosure vulnerability.

Description

The remote host is running Novell Messenger Server, formerly Groupwise Messenger, an instant messaging server application.

Versions of Novell Messenger Server earlier than 2.2.1 are potentially affected by an information disclosure vulnerability whereby a remote, unauthenticated attacker could send commands that would force the Messenger server process to return the contents of arbitrary memory locations. This data could potentially include strings containing the credentials used by Messenger to authenticate to directory services.

Solution

Upgrade to Novell Messenger 2.2.1 or later.

See Also

http://www.novell.com/support/viewContent.do?externalId=7009634

Plugin Details

Severity: Medium

ID: 6057

Family: Generic

Published: 11/2/2011

Updated: 3/6/2019

Nessus ID: 56691

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:novell:messenger

Patch Publication Date: 10/25/2011

Vulnerability Publication Date: 10/25/2011

Reference Information

CVE: CVE-2011-3179

BID: 50433