CVE-2011-0914: Buffer Overflow
Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0914?
CVE-2011-0914 has a severity rating that indicates it could allow remote code execution through a heap-based buffer overflow.
How do I fix CVE-2011-0914?
To fix CVE-2011-0914, update your IBM Lotus Domino server to a version that is not vulnerable, preferably version 8.5.3 or later.
What versions of IBM Lotus Domino are affected by CVE-2011-0914?
CVE-2011-0914 affects multiple versions of IBM Lotus Domino including 5.0, 6.0, 7.0, and all versions prior to 8.5.3.
What type of vulnerability is CVE-2011-0914?
CVE-2011-0914 is classified as a heap-based buffer overflow vulnerability due to an integer signedness error.
Can CVE-2011-0914 be exploited remotely?
Yes, CVE-2011-0914 can be exploited remotely by attackers using specially crafted GIOP client requests.