CVE-2008-1217: Code Injection
Published Mar 9, 2008
·Updated
Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.
Affected Software
3 affected components
IBM Lotus Notes=6.5
IBM Lotus Notes=7.0.2
IBM Lotus Notes=8.0.0
Event History
Mar 9, 2008
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1217?
CVE-2008-1217 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2008-1217?
To fix CVE-2008-1217, update IBM Lotus Notes to the latest version, specifically to at least 7.0.2 or 8.0.1.
3
Which versions of IBM Lotus Notes are affected by CVE-2008-1217?
CVE-2008-1217 affects IBM Lotus Notes versions 6.5, 7.0.x before 7.0.2, and 8.0.x before 8.0.1.
4
What type of vulnerability is CVE-2008-1217?
CVE-2008-1217 is classified as a remote code execution vulnerability.
5
Can CVE-2008-1217 be exploited through email?
Yes, CVE-2008-1217 can be exploited via a crafted email attachment sent over SMTP.