PT-2006-2932 · Ibm · Ibm Lotus Notes
Publicado
2006-04-20
·
Atualizado
2008-09-05
·
CVE-2006-1948
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Notes versions 6.0 through 6.5 before 20060331
Description
The issue concerns the
AddSenderToAddressBook operation and NameHelper.lss in IBM Lotus Notes. It does not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow remote attackers to trick a user into sending e-mail to an unauthorized recipient.Recommendations
For versions 6.0 through 6.5 before 20060331, consider disabling the
AddSenderToAddressBook operation until a patch is available to prevent potential exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Lotus Notes