CVE-2014-0892
Summary
| CVE | CVE-2014-0892 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-23 19:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Domino | 8.5.0 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.0.1 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1.1 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1.2 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1.3 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1.4 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.1.5 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.2.0 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.2.1 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.2.2 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.2.3 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.2.4 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.0 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.1 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.2 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.3 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.4 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.5 | All | All | All |
| Application | Ibm | Lotus Domino | 8.5.3.6 | All | All | All |
| Application | Ibm | Lotus Domino | 9.0.0.0 | All | All | All |
| Application | Ibm | Lotus Domino | 9.0.1.0 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.0.0 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.0 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.1 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.2 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.4 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.1.5 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.2.0 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.2.1 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.2.2 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.2.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.1 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.2 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.4 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.5 | All | All | All |
| Application | Ibm | Lotus Notes | 8.5.3.6 | All | All | All |
| Application | Ibm | Lotus Notes | 9.0.0.0 | All | All | All |
| Application | Ibm | Lotus Notes | 9.0.1.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#350089 - IBM Notes and Domino on x86 Linux specify an executable stack | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| IBM Security Bulletin: IBM Notes & Domino fixes for multiple vulnerabilities (CVE-2014-0892 and Oracle Java Critical Patch Updates for Oct 2013, Jan 2014) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.