First published: Fri May 25 2012(Updated: )
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Quickr | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2176 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2012-2176, update IBM Lotus Quickr to version 8.2.0.27-002a or later.
CVE-2012-2176 affects IBM Lotus Quickr version 8.2 prior to 8.2.0.27-002a.
Attackers can exploit CVE-2012-2176 to execute arbitrary code on the affected system.
Yes, user interaction is typically required to trigger the vulnerability through the ActiveX control.