[NEWS] IBM Lotus Domino IMAP Buffer Overflow Vulnerability
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 25 Oct 2007 16:06:42 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
- - - - - - - - -
IBM Lotus Domino IMAP Buffer Overflow Vulnerability
<http://www-142.ibm.com/software/sw-lotus/domino> IBM Lotus Domino Server
software provides messaging, calendaring and scheduling capabilities on a
variety of operating systems. More information about the product is
available at the following URL.
Remote exploitation of a buffer overflow vulnerability within IBM Corp.'s
Lotus Domino allows attackers to execute arbitrary code in the context of
the IMAP service.
* Lotus Domino version 220.127.116.11 running on Linux as well as Windows Server
* Previous versions, as well as builds for other platforms, are suspected
to be vulnerable.
This vulnerability exists within the IMAP component of a Domino Server.
The problem specifically lies in the handling of mailbox names within
specific commands. If a user has subscribed to a mailbox with an overly
long name, certain commands will copy the user-supplied mailbox name into
a fixed-size stack buffer without proper validation.
Exploitation allows attackers to execute arbitrary code in the context of
the IMAP service. In order to conduct the attack, the attacker must be
able to establish a TCP session with the IMAP service on TCP port 143.
Valid credentials are required to access the vulnerable code.
Under Windows, the privileges gained are (by default) that of the SYSTEM
user. This allows an attacker to take complete control of the compromised
Although the UNIX version of the service does not run as root, it does run
as the same user as many other components of the Lotus Domino Server.
Because of this an attacker may gain access to sensitive information or be
able to maliciously subvert the system in other ways.
Employing firewalls to limit access to the affected service will mitigate
exposure to this vulnerability.
IBM Lotus has addressed this vulnerability within versions 6.5.6 Fix Pack
2 (FP2), 7.0.3 and 8.0 of Lotus Domino. For more information, visit the
* 06/27/2007 Initial vendor notification
* 06/28/2007 Initial vendor response
* 10/23/2007 Coordinated public disclosure
The information has been provided by iDefense.
The original article can be found at:
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NT] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities
- Next by Date: [NEWS] IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability
- Previous by thread: [NT] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities
- Next by thread: [NEWS] IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability