Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4222

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2007-4222
Last Modified 05 Sep 2008 05:27:42
Published 29 Oct 2007 06:46:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2007-4222

Summary

Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.

Vulnerable Systems

Application

  • Ibm Lotus Notes 7.0.2


References

BID - 26200

CONFIRM - http://www-1.ibm.com/support/docview.wss?rs=477&uid=swg21272930

XF - notes-html-bo(37363)

SECTRACK - 1018857

IDEFENSE - 20071023 IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability


Last Updated: 27 May 2016 10:45:48