VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3407
lotus_domino: Stack-based buffer overflow in the MailCheck821Addr...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3407

Original

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-09-16
Source Information Category:
Advisory, Alert
Last Updated:
2010-09-17




Affected Product Tags
cpe:/a:ibm:lotus_domino:8.0
cpe:/a:ibm:lotus_domino:8.0.1
cpe:/a:ibm:lotus_domino:8.0.2
cpe:/a:ibm:lotus_domino:8.0.2.1
cpe:/a:ibm:lotus_domino:8.0.2.2
cpe:/a:ibm:lotus_domino:8.0.2.3
cpe:/a:ibm:lotus_domino:8.0.2.4
cpe:/a:ibm:lotus_domino:8.5.0
cpe:/a:ibm:lotus_domino:8.5.0.1
cpe:/a:ibm:lotus_domino:8.5.1
cpe:/a:ibm:lotus_domino:8.5.1.1
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
BID 43219




BUGTRAQ 20100914 ZDI-10-177: IBM Lotus Domino iCalendar MAILTO Stack Overflow Vulnerability




CONFIRM http://www-01.ibm.com/support/docview.wss?uid=swg21446515




CONFIRM http://labs.mwrinfosecurity.com/advisories/lotus_domino_ical_stack_buffer_overflow/




EXPLOIT-DB 15005




MISC http://www.zerodayinitiative.com/advisories/ZDI-10-177/




MISC http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/af36678d60bd74288525778400534d7c?OpenDocument




MISC http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/613a204806e3f211852576e2006afa3d?OpenDocument




MISC http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/52f9218288b51dcb852576c600741f72?OpenDocument




MISC http://labs.mwrinfosecurity.com/files/Advisories/mwri_lotus-domino-ical-stack-overflow_2010-09-14.pdf




SECTRACK 1024448




SECUNIA 41433




VUPEN ADV-2010-2381




Vulnerability Type Buffer Errors (CWE-119)




XF lotus-domino-icalendar-bo(61790)





Copyright © 2010 JPCERT/CC All Rights Reserved.