Lotus Notes MIF attachment viewer buffer overflow
Added: 01/30/2008CVE: CVE-2007-5909
BID: 26175
OSVDB: 40791
Background
Lotus Notes is the client for Lotus Domino servers.Problem
A buffer overflow in the KeyView Viewer included in Lotus Notes allows command execution when a user views a specially crafted Frame Maker Interchange File (MIF) attachment.Resolution
Upgrade to Lotus Notes 7.0.3 or higher.References
http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111Limitations
Exploit works on Lotus Notes 7.0.2 and requires a user to view a MIF attachment.Platforms
Windows 2000Windows XP
Back to exploit index