SMTP: IBM Lotus Domino nrouter.exe iCalendar MAILTO Stack Buffer Overflow

This signature detects attempts to exploit a known stack buffer overflow vulnerability in IBM Lotus Domino Server. It is due an error in processing e-mail messages containing iCalendar requests. A remote unauthenticated attacker could leverage this by sending a malicious iCalendar e-mail message to a target server. A successful attack can lead to the execution of arbitrary code on a target server, within the security context of the affected service. In an unsuccessful attack, the target server can terminate abnormally.

Extended Description

IBM Lotus Domino is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input. Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the 'nrouter.exe' Lotus Domino server process. Failed attacks will cause denial-of-service conditions. Versions prior to IBM Lotus Domino 8.0.2 Fix Pack 5, 8.5.1 Fix Pack 2, and 8.5.2 are vulnerable.

Affected Products

Ibm lotus_domino

Short Name
SMTP:MAL:LOTUS-MAILTO
Severity
Major
Recommended
False
Recommended Action
None
Category
SMTP
Keywords
Buffer CVE-2010-3407 Domino IBM Lotus MAILTO Overflow Stack bid:43219 iCalendar nrouter.exe
Release Date
12/06/2010
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Ibm

CVSS Score

9.3

Found a potential security threat?