MEDIUM · 5.0

CVE-2014-0892

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by le...

Vulnerability Description

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmLotus Domino8.5.0
LinuxLinux KernelAll versions
IbmLotus Notes8.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0892?

CVE-2014-0892 is a vulnerability with a CVSS score of 5.0 (MEDIUM). IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by le...

How severe is CVE-2014-0892?

CVE-2014-0892 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0892?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Domino, Linux Linux Kernel, Ibm Lotus Notes.