Lucene search

K
saintSAINT CorporationSAINT:A573F8E2A67A49EC81E9DBAF81A0641D
HistoryMay 30, 2008 - 12:00 a.m.

IBM Lotus Sametime Community Services Multiplexer buffer overflow

2008-05-3000:00:00
SAINT Corporation
download.saintcorporation.com
12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.969

Percentile

99.7%

Added: 05/30/2008
CVE: CVE-2008-2499
BID: 29328
OSVDB: 45610

Background

IBM Lotus Sametime is enterprise instant messaging and web conferencing software.

Problem

A buffer overflow vulnerability in the Community Services Multiplexer allows remote attackers to execute arbitrary commands by requesting a long, specially crafted URL.

Resolution

Upgrade to Sametime 8.0.1 or apply one of the workarounds described in the Technote.

References

<http://www.zerodayinitiative.com/advisories/ZDI-08-028/&gt;

Limitations

Exploit works on IBM Lotus Sametime 8.0.

Platforms

Windows 2000
Windows Server 2003

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.969

Percentile

99.7%