Groove Workspace Input Validation Error in Processing SharePoint Lists Lets Remote Users Execute Scripting Code
|
|
SecurityTracker Alert ID: 1014017
|
|
SecurityTracker URL: http://securitytracker.com/id?1014017
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: May 20 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 2.5N Build 1871 and 3.1A Build 2364
|
Description: Some vulnerabilities were reported in Groove Workspace in the processing of SharePoint data. A remote user may be able to cause arbitrary scripting code to be executed.
Groove Workspace does not properly validate data contained within SharePoint lists when importing the data.
A remote user can
insert specially crafted scripting code within a drop-down menu to cause the scripting code to be executed when the SharePoint list
is imported by a target user.
A remote user can also insert specially crafted scripting code within picture columns to cause
the scripting code to be executed when the SharePoint list is imported by a target user.
The scripting code will execute with
the privileges of the target user.
|
Impact: A remote user can cause scripting code to be executed with the privileges of the target user.
|
Solution: The vendor has released fixed versions (2.5N Build 1871; 3.1A Build 2364), available at:
http://www.groove.net/index.cfm?pagename=DownloadsArchive
|
Vendor URL: www.groove.net/ (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 20 May 2005 02:08:17 -0400
Subject: http://www.groove.net/index.cfm?pagename=Support_Overview
|
> Important Security Update
> Analysis has identified security vulnerability in the Groove Virtual Office client
> software that warranted immediate attention to correct. While we aren't aware of any
> incidents that have affected our users, we have responded immediately by eliminating
> the vulnerability. We encourage all of our users to update to the latest releases of
> Groove Virtual Office.
|
|