Vulnerability record · CVE-2006-0992 · published 14 April 2006
CVE-2006-0992: Novell GroupWise Messenger Accept-Language stack buffer overflow
Novell · Groupwise Messenger
Novell GroupWise Messenger before 2.0 Public Beta 2 contains a stack-based buffer overflow triggered by a long Accept-Language value that lacks a comma or semicolon. The flaw is remotely reachable over the network without authentication and can lead to arbitrary code execution on the affected client or service.
Description
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10.0 with network reachability, no authentication, and complete impact, and public exploit code exists despite no KEV listing.
What it is
Novell GroupWise Messenger before 2.0 Public Beta 2 contains a stack-based buffer overflow triggered by a long Accept-Language value that lacks a comma or semicolon. The flaw is remotely reachable over the network without authentication and can lead to arbitrary code execution on the affected client or service.
Impact
A remote attacker can execute arbitrary code in the context of the vulnerable GroupWise Messenger process, potentially gaining full control of the affected system. The CVSS 2.0 vector indicates complete confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is reached over the network (AV:N) with low complexity and no authentication required (AC:L/Au:N). No user interaction is indicated by the vector, though the description suggests the crafted Accept-Language value is processed by the messenger component.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.72833, 99.4th percentile) and public references include an Exploit-DB entry and a Metasploit blog post, indicating public exploit activity.
What to do
- Upgrade Novell GroupWise Messenger to version 2.0 Public Beta 2 or later as directed by the vendor patch references.
- Apply the vendor patch referenced in the Novell support and ZDI advisories.
- Restrict network access to GroupWise Messenger services to trusted hosts or segments where feasible.
- Monitor for and block malformed Accept-Language headers containing unusually long values without comma or semicolon delimiters.
- Retire or isolate unsupported GroupWise Messenger versions that cannot be patched.
Detection
- Inspect network traffic or logs for Accept-Language header values that are abnormally long or lack comma/semicolon delimiters.
- Monitor GroupWise Messenger process crashes or unexpected restarts that could indicate exploitation attempts.
- Use IDS/IPS signatures for known exploit patterns targeting the Accept-Language parsing path.
- Review endpoint telemetry for suspicious child processes or code execution originating from the GroupWise Messenger process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0992), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.