Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.
| Software | From | Fixed in |
|---|---|---|
| novell / groupwise_messenger | 2.0.2 | 2.0.2.x |
| novell / groupwise_messenger | 2.0.3 | 2.0.3.x |
| novell / groupwise_messenger | 2.0 | 2.0.x |