CVE-2014-0892: Infoleak
IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0892?
CVE-2014-0892 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2014-0892?
To address CVE-2014-0892, upgrade to IBM Notes and Domino version 8.5.3 FP6 IF3 or 9.0.1 FP1 or later.
Which versions are affected by CVE-2014-0892?
CVE-2014-0892 affects IBM Notes and Domino versions 8.5.x below 8.5.3 FP6 IF3 and 9.x below 9.0.1 FP1 on 32-bit Linux.
What type of vulnerability is CVE-2014-0892?
CVE-2014-0892 is a buffer overflow vulnerability that can allow remote attackers to execute arbitrary code.
Is there a workaround for CVE-2014-0892?
There is no specific workaround for CVE-2014-0892; upgrading to a patched version is the recommended action.