20110524 IBM Lotus Notes LZH Attachment Viewer Stack Buffer OverflowThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=904 CVE-2011-1213
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
Record summary
CVE-2011-1213 has a selected CVSS score of 9.3; EIP currently links 3 catalogued exploits.
Description
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBLotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
MetasploitLotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)Metasploit exploitby alino <26alino@gmail.com> +1 moreNot analyzed1 file
MetasploitLotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)Metasploit exploitby alino <26alino@gmail.com> +1 moreNot analyzed1 file
References
844624Third-party advisory
http://secunia.com/advisories/44624 8285Third-party advisory
http://securityreason.com/securityalert/8285 ibm.comConfirmation
http://www.ibm.com/support/docview.wss?uid=swg21500034 47962vdb entry
http://www.securityfocus.com/bid/47962 lotus-notes-lzhsr-bo(67620)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/67620 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-1213 oval:org.mitre.oval:def:14634vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14634