CVE-2018-1771: Buffer Overflow
Published Dec 20, 2018
·Updated
IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.
Affected Software
19 affected components
IBM Domino>=9.0.1.0<=9.0.1.10
IBM Domino=9.0.0.0-if1
IBM Domino=9.0.0.0-if2
IBM Domino=9.0.0.0-if3
IBM Domino=9.0.0.0-if4
IBM Domino=9.0.1.10-if1
IBM Domino=9.0.1.10-if2
IBM Domino=9.0.1.10-if3
IBM Domino=9.0.1.10-if4
IBM Notes>=9.0.1.0<=9.0.1.10
IBM Notes=9.0.0.0-if1
IBM Notes=9.0.0.0-if2
IBM Notes=9.0.0.0-if3
IBM Notes=9.0.0.0-if4
IBM Notes=9.0.1.10-if1
IBM Notes=9.0.1.10-if2
IBM Notes=9.0.1.10-if3
IBM Notes=9.0.1.10-if4
IBM Notes=9.0.1.10-if5
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1771.
2
What is the severity of vulnerability CVE-2018-1771?
The severity of vulnerability CVE-2018-1771 is high (7.8).
3
What is the affected software for vulnerability CVE-2018-1771?
The affected software for vulnerability CVE-2018-1771 is IBM Domino 9.0 and 9.0.1, as well as IBM Notes 9.0 and 9.0.1.
4
How does the vulnerability CVE-2018-1771 allow an attacker to execute commands on the system?
The vulnerability CVE-2018-1771 allows an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe.
5
How can I fix vulnerability CVE-2018-1771?
To fix vulnerability CVE-2018-1771, update your IBM Domino and IBM Notes software to version 9.0.1.10 or later.