fhs
Volume 7, Number 45 -- December 4, 2007

Patch Available for Lotus Notes Security Flaw

Published: December 4, 2007

by Alex Woodie

IBM is helping to distribute a patch for a security vulnerability discovered in a Lotus Notes file viewer that could allow an attacker to take full control of an affected computer. IBM says the flaw, which was disclosed last week by Core Security Technologies, only affects the Lotus Notes client, and not the Domino server. A patch is available for Notes version 7 and 8.

Sebastián Muñiz from the Core Impact Exploit Writers Team (EWT) at Core\r\nSecurity Technologies is credited with discovering a buffer overflow vulnerability in a third-party file viewer that's used to open Lotus 1-2-3 e-mail attachments. According to Core, the vulnerability in the Lotus WorkSheet file processor, which is developed by the software company Autonomy and which IBM distributes as a component of Notes, could allow an attacker to execute arbitrary code when they get a victim to open a corrupt Lotus 1-2-3 file sent as an e-mail attachment.

IBM and Autonomy were alerted to the flaw, and worked together to develop a patch for Notes versions 7 and 8. Notes customers are encouraged to contact IBM to obtain the patch, according to IBM's Technote on the problem.

The problem also affects Notes versions 5 and 6. In lieu of a patch, users are encouraged to work around the flaw by disabling the Autonomy file viewer. Instructions on how to do this are available in the IBM Technote.

The flaw represents a severe threat to organizations that use Lotus Notes for e-mail, says Core Security CTO Ivan Arce. "The discovery of this vulnerability in the Lotus Notes client underlines, once again, that securing endpoint systems and the applications that run on them is critical," he says, "and that no vendor is immune to the perils of client application security."




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
AFFIRMATIVE COMPUTER

For tough production and warehouse environments,
Affirmative introduces the industrial-strength YEStablet wireless thin client.

Featuring a magnesium alloy case and shock protection boot
for industrial applications, the new YEStablet supports 5250 and 3270 emulation
with built-in GUI and touch-screen keyboard.

The USB port supports barcode scanners and other data collection devices.
Vehicle mount and wearable options are also available.

Visit www.affirmative.net for more information.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

DRV Technologies:  Automatically convert and distribute AS/400 reports with SpoolFlex
Computer Measurement Group:  CMG '07 International Conference, December 2-7, San Diego
COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee


 

IT Jungle Store Top Book Picks

The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
State of the System i: How 2007 Went for Tool Vendors, and How 2008 Is Looking

Emerging Markets and Virtualization Drive Q3 Server Sales

IBM Readies Power Management for Power Servers

Bleak Outlook for Information Security, According to Researchers

The Linux Beacon
Blade Servers Make It to the Top HPC Sites

Red Hat and Platform Computing Partner for Supercomputing

HP Closes Out Fiscal 2007 with a Strong Finish

Be My Guest

Big Iron
IBM Previews z/VSE V4.2, Releases DB2 Server V7.5

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
System i Developers and .NET 2.0, Part 2: Web Development Using ASP.NET AJAX

ON vs. ON

Admin Alert: Basic Tools for the System i Admin Tool Chest

System i PTF Guide
November 24, 2007: Volume 9, Number 46

November 17, 2007: Volume 9, Number 45

November 10, 2007: Volume 9, Number 45

November 3, 2007: Volume 9, Number 44

October 27, 2007: Volume 9, Number 43

October 20, 2007: Volume 9, Number 42

The Windows Observer
Bleak Outlook for Information Security, According to Researchers

Emerging Markets and Virtualization Drive Q3 Server Sales

New Windows Operating Systems Put to the Speed Test

HP Closes Out Fiscal 2007 with a Strong Finish

The Unix Guardian
Emerging Markets and Virtualization Drive Q3 Server Sales

Dell Finally and Officially Supports Solaris

Transitive Ships Sparc/Solaris Emulator, Partners with Hitachi

As I See It: The Sick Guys in Your Wallet

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

LANSA
New Generation Software
Maximum Availability
Clearview Software International
Affirmative Computer


Printer Friendly Version


TABLE OF CONTENTS
Profound Logic Gives Web Access to DB2/400 with iData

Sametime, But a Different Place; IBM Tries to Top Microsoft

Touchtone Boosts Communication in i5/OS CRM

NGS Delivers Prebuilt BI for Healthcare

News Briefs and Product Shorts:

SafeData Launches Telecom Recovery Service . . . Patch Available for Lotus Notes Security Flaw . . . Utah Distributor Picks IBS for Supply Chain Management . . . Link Likes look for System i Modernization . . . New World Sells an i5/OS Solution--And 13 More for Windows . . . Calypso Sings Praise of Inovis for EDI . . .

Four Hundred Stuff

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement