PT-2007-5652 · Ibm · Ibm Lotus Domino
E.B
·
Published
2007-12-27
·
Updated
2017-09-29
·
CVE-2007-4474
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Domino versions 6.x through 7.x
Description
The issue is related to multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control. This can be exploited by remote attackers to execute arbitrary code. The overflow can occur from a long
General ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module.Recommendations
For versions 6.x through 7.x, consider disabling the
InstallBrowserHelperDll function in the Upload Module as a temporary workaround until a patch is available. Restrict access to the ActiveX controls provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll to minimize the risk of exploitation. Avoid using long values for the General ServerName property in the affected control until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Lotus Domino