Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.
| Software | From | Fixed in |
|---|---|---|
| novell / groupwise_messenger | 2.0.2 | 2.0.2.x |
| novell / groupwise_messenger | 1.0.6 | 1.0.6.x |
| novell / groupwise_messenger | 2.0.3 | 2.0.3.x |
| novell / groupwise_messenger | 2.0 | 2.0.x |