CVE-2007-1675
IBM Lotus Domino IMAP Server CRAM-MD5 Authentication Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.
Desbordamiento de búfer en el mecanismo de autenticación CRAM-MD5 del servidor IMAP (nimap.exe) de IBM Lotus Domino anterior a 6.5.6 y 7.x anterior a 7.0.2 FP1 permite a atacantes remotos provocar una denegación de servicio mediante un nombre de usuario largo.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Domino Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the CRAM-MD5 authentication mechanism of nimap.exe which binds by default to TCP port 143. No check is done on the length on the supplied username prior to processing it through a custom copy loop. If the username is longer than 256 bytes, a pointer overwrite may occur in the function nnotes.dll.CStream::ToBase64() which is later called and can therefore result in execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-03-24 CVE Reserved
- 2007-03-28 CVE Published
- 2007-03-29 First Exploit
- 2024-05-23 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/23172 | Vdb Entry | |
http://www.securitytracker.com/id?1017823 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1133 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-07-011.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33276 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/3602 | 2007-03-29 | |
https://www.exploit-db.com/exploits/3616 | 2007-03-31 | |
https://www.exploit-db.com/exploits/4207 | 2007-07-20 |
URL | Date | SRC |
---|---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg21257028 | 2017-07-29 | |
http://www.securityfocus.com/bid/23173 | 2017-07-29 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/24633 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.0 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.1 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.2 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.3 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.4 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.4 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.4" | fp1 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.4 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.4" | fp2 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.5 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.5 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.5" | fp1 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 6.5.5 Search vendor "Ibm" for product "Lotus Domino" and version "6.5.5" | fp2 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 7.0 Search vendor "Ibm" for product "Lotus Domino" and version "7.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 7.0.1 Search vendor "Ibm" for product "Lotus Domino" and version "7.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Domino Search vendor "Ibm" for product "Lotus Domino" | 7.0.2 Search vendor "Ibm" for product "Lotus Domino" and version "7.0.2" | - |
Affected
|