IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
BID:10600
Info
IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
| Bugtraq ID: | 10600 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0480 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Jouko Pynnönen. |
| Vulnerable: |
IBM Lotus Notes 6.5.1 IBM Lotus Notes 6.5 IBM Lotus Notes 6.0.3 IBM Lotus Notes 6.0.2 IBM Lotus Notes 6.0.1 IBM Lotus Notes 6.0 IBM Lotus Notes 5.0.12 |
| Not Vulnerable: |
IBM Lotus Notes 6.5.2 IBM Lotus Notes 6.0.4 |
Discussion
IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
A vulnerability is reported to affect the way Lotus Notes URIs are handled. The vulnerability exists due to a lack of sufficient input validation performed on Lotus Notes URIs.
By controlling influencing notes.ini content, it is possible for a remote attacker to execute arbitrary code.
Code execution will occur in the context of the user who is running the vulnerable instance of Lotus Notes.
It should be noted that this issue is not present in Lotus Notes R5 or 4.6x.
A vulnerability is reported to affect the way Lotus Notes URIs are handled. The vulnerability exists due to a lack of sufficient input validation performed on Lotus Notes URIs.
By controlling influencing notes.ini content, it is possible for a remote attacker to execute arbitrary code.
Code execution will occur in the context of the user who is running the vulnerable instance of Lotus Notes.
It should be noted that this issue is not present in Lotus Notes R5 or 4.6x.
Exploit / POC
IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
Exploit is not required.
Exploit is not required.
Solution / Fix
IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
Solution:
IBM has released an advisory to address this issue. The vendor reports that this vulnerability is addressed with the release of Lotus Notes versions 6.0.4 and 6.5.2.
Solution:
IBM has released an advisory to address this issue. The vendor reports that this vulnerability is addressed with the release of Lotus Notes versions 6.0.4 and 6.5.2.
References
IBM Lotus Notes URI Handler Remote Code Execution Vulnerability
References:
References: