First published: Tue Apr 21 2015(Updated: )
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =8.5.0 | |
IBM Lotus Domino | =8.5.1 | |
IBM Lotus Domino | =8.5.2 | |
IBM Lotus Domino | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0135 is considered a critical vulnerability due to its potential to allow remote code execution or cause a denial of service.
To fix CVE-2015-0135, upgrade IBM Domino to version 8.5.3 FP6 IF4 or 9.0.1 FP3 IF2 or later.
CVE-2015-0135 can be exploited by attackers to execute arbitrary code or crash the application through specially crafted GIF images.
CVE-2015-0135 affects IBM Domino versions 8.5.0, 8.5.1, 8.5.2, and 9.0.1 prior to their respective fix packs.
While specific exploitation details may vary, vulnerabilities such as CVE-2015-0135 are often targeted by attackers due to their critical nature.