• On TV.com: TOP 10 Shows CANCELED Too Soon

News Blog

Read all 'Lotus 1-2-3' posts in News Blog
November 28, 2007 7:45 AM PST

IBM patches Lotus Notes 1-2-3 security flaws

by Dawn Kawamoto
  • Post a comment

IBM has released a patch for highly critical security flaws in its Lotus Notes, following the discovery of vulnerabilities in a third-party software component used in Lotus 1-2-3.

Users who open a malicious file attachment can trigger a buffer overflow, as Lotus 1-2-3 tries to process the Lotus Worksheet file format. The vulnerabilities could allow a malicious attacker to take control of a user's system remotely and execute arbitrary code, according to Core Security Technologies, which issued a security advisory on Tuesday.

(Credit: IBM)

"Although these specific vulnerabilities exist on a third-party component, the problem is compounded by the way Lotus Notes displays information about attachments, making it easier to elicit unsuspecting assistance from the users to exploit them," Core Security's advisory notes.

Attackers, for example, could send a malicious Lotus 1-2-3 file attachment with a common extension of .jpg or .gif, rather than a MIME Content-type e-mail header.

Big Blue is advising customers to contact IBM support to receive the patch, which is available for Notes 7x and 8x client versions. The company also notes that the security flaws affect only Windows-based Notes clients. Lotus Domino server users are not affected.

Lotus Notes, which includes a combination of e-mail, instant messenger, browser and business collaboration applications, is a desktop client that is designed to work with Lotus Domino. Security researcher Secunia is rating the Lotus Notes vulnerabilities as "highly critical."

  • prev
  • 1
  • next
advertisement
Click Here

E-readers' next chapter--no happy ending?

There were plenty of e-book readers on display at CES 2010, but many question whether the market for such dedicated devices can support all the new entrants.
• Photos: E-readers at CES 2010

Inside the world's long-lost first microcomputer

Vintage computer historians have long revered the Altair 8800. As it turns out, an unknown computer project at Sacramento State beat the Altair by three years.
• Images: The first microcomputers

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader



advertisement

Inside CNET News

Scroll Left Scroll Right