Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.901157
Categoría:Buffer overflow
Título:IBM Lotus Domino iCalendar Remote Stack Buffer Overflow Vulnerability
Resumen:IBM Lotus Domino Server is prone to remote stack buffer overflow vulnerability.
Descripción:Summary:
IBM Lotus Domino Server is prone to remote stack buffer overflow vulnerability.

Vulnerability Insight:
The flaw is due to a boundary error in the 'MailCheck821Address()'
function within nnotes.dll when copying an email address using the
'Cstrcpy()' library function. This can be exploited to cause a stack-based
buffer overflow via an overly long 'ORGANIZER:mailto' iCalendar header.

Vulnerability Impact:
Successful exploitation may allow remote attackers to execute arbitrary code
in the context of the 'nrouter.exe' Lotus Domino server process. Failed
attacks will cause denial-of-service conditions.

Affected Software/OS:
IBM Lotus Domino Versions 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2

Solution:
Upgrade to IBM Lotus Domino version 8.5.2, 8.5.1 Fix Pack 2 or 8.0.2 Fix Pack 5.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-3407
BugTraq ID: 43219
http://www.securityfocus.com/bid/43219
Bugtraq: 20100914 ZDI-10-177: IBM Lotus Domino iCalendar MAILTO Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/513706/100/0/threaded
http://www.exploit-db.com/exploits/15005
http://labs.mwrinfosecurity.com/files/Advisories/mwri_lotus-domino-ical-stack-overflow_2010-09-14.pdf
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/52f9218288b51dcb852576c600741f72?OpenDocument
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/613a204806e3f211852576e2006afa3d?OpenDocument
http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/af36678d60bd74288525778400534d7c?OpenDocument
http://www.zerodayinitiative.com/advisories/ZDI-10-177/
http://securitytracker.com/id?1024448
http://secunia.com/advisories/41433
http://www.vupen.com/english/advisories/2010/2381
XForce ISS Database: lotus-domino-icalendar-bo(61790)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61790
CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.