CVE-2010-3407
Last modified
CVE-2010-3407 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.. EPSS estimates a 41.48% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Domino | 8.0 |
| Ibm | Lotus Domino | 8.0.1 |
| Ibm | Lotus Domino | 8.0.2 |
| Ibm | Lotus Domino | 8.0.2.1 |
| Ibm | Lotus Domino | 8.0.2.2 |
| Ibm | Lotus Domino | 8.0.2.3 |
| Ibm | Lotus Domino | 8.0.2.4 |
| Ibm | Lotus Domino | 8.5.0 |
| Ibm | Lotus Domino | 8.5.0.1 |
| Ibm | Lotus Domino | 8.5.1 |
| Ibm | Lotus Domino | 8.5.1.1 |
References
- http://secunia.com/advisories/41433Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21446515Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2381Vendor Advisory
- http://secunia.com/advisories/41433Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21446515Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2381Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3407?
How severe is CVE-2010-3407?
How do I fix CVE-2010-3407?
Are you affected by CVE-2010-3407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
