CVE-2015-5040: Buffer Overflow
Buffer overflow in IBM Domino 8.5.1 through 8.5.3 before 8.5.3 FP6 IF10 and 9.x before 9.0.1 FP4 IF3 allows remote attackers to execute arbitrary code or cause a denial of service (SMTP daemon crash) via a crafted GIF image, aka SPRs KLYH9ZDKRE and KLYH9ZTLEZ, a different vulnerability than CVE-2015-4994.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5040?
CVE-2015-5040 is classified as a critical vulnerability due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2015-5040?
To fix CVE-2015-5040, upgrade IBM Domino to version 8.5.3 FP6 IF10 or later, or to version 9.0.1 FP4 IF3 or later.
What software versions are affected by CVE-2015-5040?
CVE-2015-5040 affects IBM Domino versions 8.5.1 through 8.5.3 prior to FP6 IF10 and 9.x prior to 9.0.1 FP4 IF3.
Can CVE-2015-5040 cause a denial of service?
Yes, CVE-2015-5040 can cause a denial of service by crashing the SMTP daemon through a crafted GIF image.
What types of attacks can exploit CVE-2015-5040?
CVE-2015-5040 can be exploited for remote code execution or denial of service attacks by sending a specially crafted GIF image.