Vigil@nce: Lotus iNotes, 2 vulnerabilities
March 2010 by Vigil@nce
Two vulnerabilities were announced in Lotus iNotes (DWA, Domino Web Access).
Severity: 2/4
Consequences: user access/rights, client access/rights
Provenance: document
Means of attack: no proof of concept, no attack
Ability of attacker: expert (4/4)
Confidence: confirmed by the editor (5/5)
Diffusion of the vulnerable configuration: high (3/3)
Number of vulnerabilities in this bulletin: 2
Creation date: 01/03/2010
IMPACTED PRODUCTS
Lotus Domino
DESCRIPTION OF THE VULNERABILITY
Two vulnerabilities were announced in Lotus iNotes (DWA, Domino Web Access).
An attacker can use several vulnerabilities of UltraLite. [severity:2/4]
An attacker can generate a buffer overflow in the Lotus iNotes ActiveX, in order to execute code on victim’s computer. [severity:2/4; BID-38457, PRAD7JTNHJ, swg21421808]
CHARACTERISTICS
Identifiers: BID-38457, BID-38459, PRAD7JTNHJ, swg21421808,
swg27018109, VIGILANCE-VUL-9482
Url: http://vigilance.fr/vulnerability/L...





News





