Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902298
Categoría:General
Título:IBM Lotus Notes 'cai' URI and iCal Remote Code Execution Vulnerabilities (Windows)
Resumen:This host has IBM Lotus Notes installed and is prone to remote code; execution vulnerabilities.
Descripción:Summary:
This host has IBM Lotus Notes installed and is prone to remote code
execution vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- An input validation error when processing the '--launcher.library' switch
within a 'cai:' URI, which could allow attackers to load a malicious
library.

- A buffer overflow error related to 'iCal', which could be exploited by
attackers to execute arbitrary code.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary code in the
context of the user running the application.

Affected Software/OS:
IBM Lotus Notes Version 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 on windows

Solution:
Upgrade to IBM Lotus Notes 8.0.2 FP6 or 8.5.1 FP5

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-0912
http://zerodayinitiative.com/advisories/ZDI-11-051/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14348
http://secunia.com/advisories/43222
http://www.vupen.com/english/advisories/2011/0295
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.