CVE-2015-1903: Buffer Overflow
Published May 20, 2015
·Updated
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSN3Y.
Affected Software
5 affected components
IBM Domino=8.5.0
IBM Domino=8.5.1
IBM Domino=8.5.2
IBM Domino=8.5.3
IBM Domino=9.0.1
Remediation
Patch Available
Event History
May 20, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1903?
CVE-2015-1903 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2015-1903?
To mitigate CVE-2015-1903, update IBM Domino to version 8.5.3 FP6 IF7 or 9.0.1 FP3 IF3 or later.
3
What types of attacks are possible with CVE-2015-1903?
CVE-2015-1903 allows remote attackers to execute arbitrary code via crafted BMP images.
4
Which versions of IBM Domino are affected by CVE-2015-1903?
CVE-2015-1903 affects IBM Domino versions 8.5.0 through 8.5.3 and 9.0.1 prior to FP3 IF3.
5
Is CVE-2015-1903 easy to exploit?
Yes, CVE-2015-1903 is considered easy to exploit, which increases its risk for organizations using the affected versions.