Release date:
Updated on:
Affected Systems:
IBM Lotus iNotes
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53879
Cve id: CVE-2012-2175
Lotus iNotes, formerly known as Lotus Domino Web Access, is a web-based messaging and collaboration interface for Lotus Domino servers.
In earlier versions of IBM Lotus iNotes 8.5.3 FP2, The Attachment_Times method in some ActiveX controls in dwa85W. dll has a buffer overflow vulnerability. A long parameter allows remote attackers to execute arbitrary code.
<* Source: vendor
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg21596862
Http://xforce.iss.net/xforce/xfdb/75321
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/