Advisories Blog | G5 Cyber Security

iDEFENSE Security Advisory 2007-03-29.1

iDefense Security Advisory 03.29.07 – Remote exploitation of a input validation vulnerability in IBM Corp.’s Lotus Sametime allows attackers to execute arbitrary code in the context of the user viewing a malicious web page. The problem specifically exists in the STJNILoader.ocx component of IBM Corp.’s Lotus Sametime product. This ActiveX control is safe for scripting and exports a LoadLibrary function that does not properly sanitize input. iDefense has confirmed that this vulnerability is present in IBM Corp.’s Lotus Sametime STJNILoader.ocx version 3.1.0.26.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55493/03.29.07-1.txt

Source: https://packetstormsecurity.com/files/55493/iDEFENSE-Security-Advisory-2007-03-29.1.html

Exit mobile version