IBM Lotus Notes File Attachment Handling Multiple Remote Vulnerabilities

IBM Lotus Notes is prone to multiple remote vulnerabilities. The buffer-overflow issues could allow arbitrary code execution in the context of the user running the application.

The issues are:

- A buffer overflow exists when extracting files from ZIP archives.
- A buffer overflow exists when extracting files from UUE encoded files.
- A buffer overflow exists when extracting files from TAR archives.
- A buffer overflow exists when handling HTML file attachments with malicious links.
- A directory traversal exists when generating previews of ZIP, UUE, and TAR archives. This could be exploited to overwrite arbitrary files in the context of the current user.


Lotus Notes 6.5.4 and 7.0 are prone to these issues. Other versions may also be vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus