Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.901157
Kategorie:Buffer overflow
Titel:IBM Lotus Domino iCalendar Remote Stack Buffer Overflow Vulnerability
Zusammenfassung:IBM Lotus Domino Server is prone to remote stack buffer overflow vulnerability.
Beschreibung:Summary:
IBM Lotus Domino Server is prone to remote stack buffer overflow vulnerability.

Vulnerability Insight:
The flaw is due to a boundary error in the 'MailCheck821Address()'
function within nnotes.dll when copying an email address using the
'Cstrcpy()' library function. This can be exploited to cause a stack-based
buffer overflow via an overly long 'ORGANIZER:mailto' iCalendar header.

Vulnerability Impact:
Successful exploitation may allow remote attackers to execute arbitrary code
in the context of the 'nrouter.exe' Lotus Domino server process. Failed
attacks will cause denial-of-service conditions.

Affected Software/OS:
IBM Lotus Domino Versions 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2

Solution:
Upgrade to IBM Lotus Domino version 8.5.2, 8.5.1 Fix Pack 2 or 8.0.2 Fix Pack 5.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-3407
BugTraq ID: 43219
http://www.securityfocus.com/bid/43219
Bugtraq: 20100914 ZDI-10-177: IBM Lotus Domino iCalendar MAILTO Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/513706/100/0/threaded
http://www.exploit-db.com/exploits/15005
http://labs.mwrinfosecurity.com/files/Advisories/mwri_lotus-domino-ical-stack-overflow_2010-09-14.pdf
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/52f9218288b51dcb852576c600741f72?OpenDocument
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/613a204806e3f211852576e2006afa3d?OpenDocument
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/af36678d60bd74288525778400534d7c?OpenDocument
http://www.zerodayinitiative.com/advisories/ZDI-10-177/
http://securitytracker.com/id?1024448
http://secunia.com/advisories/41433
http://www.vupen.com/english/advisories/2010/2381
XForce ISS Database: lotus-domino-icalendar-bo(61790)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61790
CopyrightCopyright (C) 2010 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.