IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
BID:29328
Info
IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
| Bugtraq ID: | 29328 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2499 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | Jul 12 2008 01:49AM |
| Credit: | Manuel Santamarina Suarez |
| Vulnerable: |
IBM Lotus Sametime 7.5.1 IBM Lotus Sametime 8.0 IBM Lotus Sametime 7.5 IBM Lotus Sametime 7.0 |
| Not Vulnerable: |
IBM Lotus Sametime 8.0.1 |
Discussion
IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
IBM Lotus Sametime is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
IBM Lotus Sametime is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
Exploit / POC
IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability
References:
References:
- IBM Homepage (IBM)
- IBM Lotus Sametime Product Page (IBM)
- ZDI-08-028: IBM Lotus Sametime Community Services Multiplexer Stack Overflow Vul ([email protected])
- Potential stack overflow vulnerability with IBM Lotus Sametime Community Service (IBM)
- ZDI-08-028 IBM Lotus Sametime Community Services Multiplexer Stack Overflow Vuln (ZDI)