1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. Web Attack: IBM Lotus iNotes CVE-2012-2175

Web Attack: IBM Lotus iNotes CVE-2012-2175

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

IBM Lotus iNotes Upload Module ActiveX Control is prone to a remote buffer-overflow vulnerability; fixes are available.

Additional Information

IBM Lotus iNotes Upload Module ActiveX Control is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds check user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition. IBM Lotus iNotes 8.5, 8.5.1, 8.5.2 and 8.5.3 are vulnerable.

Affected

  • IBM Lotus iNotes 8.5
  • IBM Lotus iNotes 8.5.1
  • IBM Lotus iNotes 8.5.2

Response

Updates are available; please see the references for more information.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube