vendor:
Lotus Domino Server
by:
A. Plaskett
7,5
CVSS
HIGH
Stack based buffer overflow
120
CWE
Product Name: Lotus Domino Server
Affected Version From: 8.0
Affected Version To: 8.5
Patch Exists: YES
Related CWE: Not Yet Assigned
CPE: a:ibm:lotus_domino_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX, AIX 64bit, Linux, Linux iSeries, Linux zSeries, Solaris, Windows, Windows 64bit, z/OS
2010
IBM Lotus Domino iCalendar Email Address Stack Buffer Overflow Vulnerability
An unauthenticated remote code execution vulnerability was identified in the code handling the conversion and checking of an iCalendar email address parameter. An overly large email address string can lead to the overflow of a stack allocated buffer due to insufficient bounds checking when a CStrcpy (string copy) is performed. A remote, unauthenticated attacker could execute code in the context of the Lotus Domino server process (nrouter.exe) by sending a specially crafted malicious email to the Lotus Domino SMTP server.
Mitigation:
A patch is available from: http://www-01.ibm.com/support/docview.wss?rs=475&uid=swg21446515