SMTP: IBM Lotus Notes Attachment Viewer UUE File Handling Buffer Overflow

This signature detects attempts to exploit a known vulnerability in IBM Lotus Notes Attachment Viewer. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

IBM Lotus Notes is prone to multiple remote vulnerabilities. The buffer-overflow issues could allow arbitrary code execution in the context of the user running the application. The issues are: - A buffer overflow exists when extracting files from ZIP archives. - A buffer overflow exists when extracting files from UUE encoded files. - A buffer overflow exists when extracting files from TAR archives. - A buffer overflow exists when handling HTML file attachments with malicious links. - A directory traversal exists when generating previews of ZIP, UUE, and TAR archives. This could be exploited to overwrite arbitrary files in the context of the current user. Lotus Notes 6.5.4 and 7.0 are prone to these issues. Other versions may also be vulnerable.

Affected Products

Ibm lotus_notes

References

BugTraq: 16576

CVE: CVE-2005-2618

Short Name
SMTP:MAL:IBM-ATTACHMENT-VIEWER
Severity
Major
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
Attachment Buffer CVE-2005-2618 File Handling IBM Lotus Notes Overflow UUE Viewer bid:16576
Release Date
07/26/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Ibm

CVSS Score

9.3

Found a potential security threat?