packetstormsecurity.com
http://packetstormsecurity.com/files/152786/Lotus-Domino-8.5.3-EXAMINE-Stack-Buffer-Overflow.html CVE-2017-1274
HIGH
IBM domino Improper Restriction of Operations within the Bounds of a Memory Buffer
Record summary
CVE-2017-1274 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 20, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DominoBrowse IBM / Domino | CVE List, VulnCheck | 8.5.3.5, 8.5.3.6, 9.0.1, 8.5, 9.0, 8.5.1, 8.5.2, 8.5.3, 9.0.1.1, 8.0.2, 8.0, 8.0.1, 8.5.1.5, 8.5.2.4, 9.0.1.2, 8.5.0.1, 9.0.1.3, 8.5.1.4, 9.0.1.4, 9.0.1.5, 8.5.1.1, 9.0.1.6, 9.0.1.7, 9.0.1.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBLotus Domino 8.5.3 - 'EXAMINE' Stack Buffer Overflow DEP/ASLR Bypass (NSA's EMPHASISMINE)ExploitDB exploitby Charles TruscottNot analyzed1 file
References
7ibm.comConfirmation
http://www.ibm.com/support/docview.wss?uid=swg22002280 97910vdb entry
http://www.securityfocus.com/bid/97910 98019vdb entry
http://www.securityfocus.com/bid/98019 1038358vdb entry
http://www.securitytracker.com/id/1038358 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-1274 VU#676632Third-party advisory
https://www.kb.cert.org/vuls/id/676632