CVE-2015-1902: Buffer Overflow
Published May 20, 2015
·Updated
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSMLA.
Affected Software
5 affected components
IBM Domino=8.5.0
IBM Domino=8.5.1
IBM Domino=8.5.2
IBM Domino=8.5.3
IBM Domino=9.0.1
Remediation
Patch Available
Event History
May 20, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1902?
CVE-2015-1902 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2015-1902?
To fix CVE-2015-1902, upgrade IBM Domino to version 8.5.3 FP6 IF7 or 9.0.1 FP3 IF3 or later.
3
What versions of IBM Domino are affected by CVE-2015-1902?
CVE-2015-1902 affects IBM Domino versions 8.5.0, 8.5.1, 8.5.2, 8.5.3 before FP6 IF7, and 9.0 before FP3 IF3.
4
How can attackers exploit CVE-2015-1902?
Attackers can exploit CVE-2015-1902 by sending a crafted BMP image to the vulnerable IBM Domino server.
5
What type of vulnerability is CVE-2015-1902?
CVE-2015-1902 is a stack-based buffer overflow vulnerability.