CVE-2008-2499: Buffer Overflow
Published May 29, 2008
·Updated
Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.
Affected Software
3 affected components
IBM Lotus Sametime<=7.5
IBM Lotus Sametime>=8.0<8.0.1
IBM Lotus Sametime=7.5.1-cf1
Event History
May 29, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2499?
CVE-2008-2499 is rated as high severity due to the potential for remote code execution.
2
How do I fix CVE-2008-2499?
To fix CVE-2008-2499, upgrade to IBM Lotus Sametime version 8.0.1 or later where the vulnerability is patched.
3
Which versions of IBM Lotus Sametime are affected by CVE-2008-2499?
CVE-2008-2499 affects IBM Lotus Sametime 7.5.1 CF1 and earlier, as well as versions prior to 8.0.1.
4
Can CVE-2008-2499 be exploited remotely?
Yes, CVE-2008-2499 can be exploited remotely through a crafted URL.
5
What type of vulnerability is CVE-2008-2499?
CVE-2008-2499 is a stack-based buffer overflow vulnerability.