Vulnerability Name: | CVE-2008-2499 (CCN-42575) | ||||||||
Assigned: | 2008-05-21 | ||||||||
Published: | 2008-05-21 | ||||||||
Updated: | 2018-10-31 | ||||||||
Summary: | Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-2499 Source: CCN Type: SA30309 IBM Lotus Sametime Community Services Multiplexer Buffer Overflow Source: SECUNIA Type: Third Party Advisory 30309 Source: CCN Type: SECTRACK ID: 1020093 Lotus Sametime Stack Overflow in Community Services MUX Lets Remote Users Execute Arbitrary Code Source: CCN Type: IBM Technote (FAQ) 1303920 Potential stack overflow vulnerability with IBM Lotus Sametime Community Services multiplexer (MUX) Source: CONFIRM Type: Vendor Advisory http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21303920 Source: CCN Type: OSVDB ID: 45610 IBM Lotus Sametime Community Services Multiplexer (StMux.exe) Remote Overflow Source: BID Type: Exploit, Third Party Advisory, VDB Entry 29328 Source: CCN Type: BID-29328 IBM Lotus Sametime Multiplexer Buffer Overflow Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1020093 Source: VUPEN Type: Third Party Advisory ADV-2008-1595 Source: MISC Type: Third Party Advisory, VDB Entry http://www.zerodayinitiative.com/advisories/ZDI-08-028/ Source: XF Type: Third Party Advisory, VDB Entry sametime-stmux-bo(42575) Source: XF Type: UNKNOWN sametime-stmux-bo(42575) Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-21-2008] IBM Lotus Domino Sametime STMux.exe Stack Buffer Overflow Source: CCN Type: ZDI-08-028 IBM Lotus Sametime Community Services Multiplexer Stack Overflow Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |