First published: Mon Oct 29 2007(Updated: )
Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Notes | <=7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4222 has a high severity rating due to its potential for remote code execution.
Mitigation for CVE-2007-4222 can be accomplished by upgrading IBM Lotus Notes to version 7.0.3 or later.
CVE-2007-4222 allows user-assisted remote attackers to execute arbitrary code through specially crafted HTML emails.
CVE-2007-4222 affects IBM Lotus Notes versions prior to 7.0.3.
CVE-2007-4222 requires user interaction for exploitation, as it depends on the recipient opening a crafted HTML email.