First published: Wed Mar 03 2010(Updated: )
Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Domino Web Access | =8.0.2 | |
Ibm Domino Web Access | =7.0 | |
Ibm Domino Web Access | =7.0.1 | |
Ibm Domino Web Access | =7.0.3 | |
Ibm Domino Web Access | =6.5 | |
Ibm Domino Web Access | =7.0.2 | |
Ibm Domino Web Access | =8.0 | |
IBM Lotus iNotes | <=229.271 | |
IBM Lotus iNotes | =229.011 | |
IBM Lotus iNotes | =229.021 | |
IBM Lotus iNotes | =229.031 | |
IBM Lotus iNotes | =229.041 | |
IBM Lotus iNotes | =229.051 | |
IBM Lotus iNotes | =229.061 | |
IBM Lotus iNotes | =229.101 | |
IBM Lotus iNotes | =229.111 | |
IBM Lotus iNotes | =229.131 | |
IBM Lotus iNotes | =229.141 | |
IBM Lotus iNotes | =229.151 | |
IBM Lotus iNotes | =229.161 | |
IBM Lotus iNotes | =229.171 | |
IBM Lotus iNotes | =229.181 | |
IBM Lotus iNotes | =229.191 | |
IBM Lotus iNotes | =229.201 | |
IBM Lotus iNotes | =229.211 | |
IBM Lotus iNotes | =229.221 | |
IBM Lotus iNotes | =229.231 | |
IBM Lotus iNotes | =229.241 | |
IBM Lotus iNotes | =229.251 | |
IBM Lotus iNotes | =229.261 | |
IBM Domino | =8.0.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0919 is considered to have a high severity rating due to its potential for remote code execution.
To fix CVE-2010-0919, update your IBM Lotus iNotes or Domino Web Access to the latest recommended version.
CVE-2010-0919 affects IBM Lotus Domino Web Access versions 6.5, 7.0 before 7.0.4, and versions 8.0, 8.0.2 before 8.0.2 FP4.
CVE-2010-0919 allows attackers to execute arbitrary code on the victim's system via a crafted long URL.
While updating the software is the best solution, temporarily disabling ActiveX controls in your browser can mitigate risk associated with CVE-2010-0919.