First published: Tue Feb 08 2011(Updated: )
Stack-based buffer overflow in the NRouter (aka Router) service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long filenames associated with Content-ID and ATTACH:CID headers in attachments in malformed calendar-request e-mail messages, aka SPR KLYH87LKRE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino Mail Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0918 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2011-0918, users should apply the latest security patches provided by IBM for Lotus Domino.
CVE-2011-0918 is a stack-based buffer overflow vulnerability in the NRouter service of IBM Lotus Domino.
CVE-2011-0918 affects all versions of IBM Lotus Domino that have the NRouter service enabled.
Attackers can exploit CVE-2011-0918 to execute arbitrary code by sending malformed calendar-request email messages with specially crafted filenames.