First published: Mon Jun 17 2013(Updated: )
Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Quickr Server | =8.1.0 | |
IBM Lotus Quickr Server | =8.2.0 | |
IBM Lotus Quickr Server | =8.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3026 is considered a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2013-3026, upgrade to at least IBM Lotus Quickr for Domino version 8.1.0.32-001a, 8.2.0.28-001a, or 8.5.1.39-002a.
CVE-2013-3026 affects IBM Lotus Quickr for Domino versions 8.1.0, 8.2.0, and 8.5.1 prior to their respective fix packs.
CVE-2013-3026 enables attackers to execute arbitrary code remotely through a crafted website.
CVE-2013-3026 is primarily a client-side vulnerability due to the exploit involving an ActiveX control.