Vulnerability Description
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Domino | 8.0 |
Related Weaknesses (CWE)
References
- http://labs.mwrinfosecurity.com/advisories/lotus_domino_ical_stack_buffer_overfl
- http://labs.mwrinfosecurity.com/files/Advisories/mwri_lotus-domino-ical-stack-ovExploit
- http://secunia.com/advisories/41433Vendor Advisory
- http://securitytracker.com/id?1024448
- http://www-01.ibm.com/support/docview.wss?uid=swg21446515Vendor Advisory
- http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/52f92Vendor Advisory
- http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/613a2Vendor Advisory
- http://www-10.lotus.com/ldd/r5fixlist.nsf/8d1c0550e6242b69852570c900549a74/af366Vendor Advisory
- http://www.exploit-db.com/exploits/15005
- http://www.securityfocus.com/archive/1/513706/100/0/threaded
- http://www.securityfocus.com/bid/43219
- http://www.vupen.com/english/advisories/2010/2381Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-177/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61790
- http://labs.mwrinfosecurity.com/advisories/lotus_domino_ical_stack_buffer_overfl
FAQ
What is CVE-2010-3407?
CVE-2010-3407 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remo...
How severe is CVE-2010-3407?
CVE-2010-3407 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3407?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Domino.