PT-2010-4797 · Ibm · Ibm Lotus Domino

A. Plaskett

·

Published

2010-09-16

·

Updated

2018-10-10

·

CVE-2010-3407

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Lotus Domino versions 8.0.x through 8.0.2 FP4 IBM Lotus Domino versions 8.5.x through 8.5.1 FP1
Description The issue is related to a stack-based buffer overflow in the MailCheck821Address function. This occurs when the nrouter.exe service processes an iCalendar calendar-invitation e-mail message with a long e-mail address in the ORGANIZER:mailto header, allowing remote attackers to execute arbitrary code.
Recommendations For IBM Lotus Domino versions 8.0.x through 8.0.2 FP4, update to version 8.0.2 FP5 or later. For IBM Lotus Domino versions 8.5.x through 8.5.1 FP1, update to version 8.5.1 FP2 or later.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3407

Affected Products

Ibm Lotus Domino