Lucene search

K
saintSAINT CorporationSAINT:9F580D17B5A0C22402DC434010FFF2EB
HistoryFeb 21, 2006 - 12:00 a.m.

Lotus Notes Attachment Viewer UUE file buffer overflow

2006-02-2100:00:00
SAINT Corporation
download.saintcorporation.com
6

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.95

Percentile

99.3%

Added: 02/21/2006
CVE: CVE-2005-2618
BID: 16576
OSVDB: 23065

Background

Lotus Notes is the client for Lotus Domino servers.

Problem

A buffer overflow in the attachment viewer in the Lotus Notes e-mail client allows command execution when a user opens a specially crafted UUE file.

Resolution

Upgrade to version 6.5.5 or 7.0.1 or higher.

References

<http://secunia.com/secunia_research/2005-36&gt;

Limitations

Exploit works on Lotus Notes 6.5.4. This exploit sends an e-mail to the specified address and requires the user to view the attachment.

Platforms

Windows

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.95

Percentile

99.3%

Related for SAINT:9F580D17B5A0C22402DC434010FFF2EB