vendor:
Lotus Domino
by:
Charles Truscott
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Lotus Domino
Affected Version From: 8.5.3 FP0
Affected Version To: 8.5.3 FP0
Patch Exists: YES
Related CWE: N/A
CPE: a:ibm:lotus_domino:8.5.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
NSA’s EMPHASISMINE for IMAP Server Lotus Domino 8.5.3 FP0 DEP/ASLR bypass
A buffer overflow vulnerability exists in the IMAP Server Lotus Domino 8.5.3 FP0 due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted request containing an overly long string of data, which can cause a stack-based buffer overflow. This can allow the attacker to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of IMAP Server Lotus Domino 8.5.3 FP0.