Release date:
Updated on:
Affected Systems:
IBM Lotus Notes <= 8.5.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46236
Lotus Notes is an integrated mail, calendar, instant messaging, browser, and Business Collaboration application developed by IBM. It can be used as a Desktop client for Lotus Domino server applications.
Lotus Notes encountered an error when processing malformed strings in cai: // URIs. "-- launcher. library "exchange will be injected and targeted to load DLL from network sharing. Remote attackers can exploit this vulnerability to execute arbitrary commands.
<* Source: rgod (rgod@autistici.org)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.ers.ibm.com/