PT-2006-2932 · Ibm · Ibm Lotus Notes
Published
2006-04-20
·
Updated
2008-09-05
·
CVE-2006-1948
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Notes versions 6.0 through 6.5 before 20060331
Description
The issue concerns the
AddSenderToAddressBook operation and NameHelper.lss in IBM Lotus Notes. It does not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow remote attackers to trick a user into sending e-mail to an unauthorized recipient.Recommendations
For versions 6.0 through 6.5 before 20060331, consider disabling the
AddSenderToAddressBook operation until a patch is available to prevent potential exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Lotus Notes