Lotus Notes Mail Recipient Information Disclosure Vulnerability
BID:19022
Info
Lotus Notes Mail Recipient Information Disclosure Vulnerability
| Bugtraq ID: | 19022 |
| Class: | Design Error |
| CVE: |
CVE-2006-3778 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Jul 05 2016 09:22PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Lotus Notes 7.0.1 IBM Lotus Notes 6.5.5 IBM Lotus Notes 6.5.4 IBM Lotus Notes 6.5.3 IBM Lotus Notes 6.5.2 IBM Lotus Notes 6.5.1 IBM Lotus Notes 6.5 IBM Lotus Notes 6.0.5 IBM Lotus Notes 6.0.4 IBM Lotus Notes 6.0.3 IBM Lotus Notes 6.0.2 IBM Lotus Notes 6.0.1 IBM Lotus Notes 6.0 IBM Lotus Notes 7.0 |
| Not Vulnerable: | |
Discussion
Lotus Notes Mail Recipient Information Disclosure Vulnerability
Lotus Notes is prone to an information-disclosure vulnerability.
The problem occurs because the 'SendTo/AltSendTo', 'CopyTo/AltCopyTo', and 'BlindCopyTo/AltBlindCopyTo' fields are not kept in sync when 'reply to all' is used.
This may result in unintended recipients receiving emails. This could result in the disclosure of sensitive information if an email containing sensitive or privileged information is sent to unintended readers.
Lotus Notes is prone to an information-disclosure vulnerability.
The problem occurs because the 'SendTo/AltSendTo', 'CopyTo/AltCopyTo', and 'BlindCopyTo/AltBlindCopyTo' fields are not kept in sync when 'reply to all' is used.
This may result in unintended recipients receiving emails. This could result in the disclosure of sensitive information if an email containing sensitive or privileged information is sent to unintended readers.
Exploit / POC
Lotus Notes Mail Recipient Information Disclosure Vulnerability
This issue requires that an attacker has previously been included in email communications.
This issue requires that an attacker has previously been included in email communications.
Solution / Fix
Lotus Notes Mail Recipient Information Disclosure Vulnerability
Solution:
IBM has released updates to address this. Please contact the vendor for more information.
Solution:
IBM has released updates to address this. Please contact the vendor for more information.
References
Lotus Notes Mail Recipient Information Disclosure Vulnerability
References:
References: