CVE-2020-14268: Buffer Overflow
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-14268?
CVE-2020-14268 is a vulnerability in the MIME message handling of the Notes client (versions 9 and 10) that could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow.
What is the severity of CVE-2020-14268?
CVE-2020-14268 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2020-14268?
CVE-2020-14268 affects Hcltech Notes versions 9.0 and 10.0, including various fix packs and interim fixes.
How can an attacker exploit CVE-2020-14268?
An attacker can exploit CVE-2020-14268 by sending a specially crafted MIME message to the vulnerable Notes client, causing a stack buffer overflow and potentially allowing them to crash the client or inject malicious code.
Is there a fix available for CVE-2020-14268?
Yes, Hcltech has provided a fix for CVE-2020-14268. Users should update to the latest version of Hcltech Notes or apply the recommended fix pack or interim fix.