• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Patch Available for Lotus Notes Security Flaw

    December 4, 2007 Alex Woodie

    IBM is helping to distribute a patch for a security vulnerability discovered in a Lotus Notes file viewer that could allow an attacker to take full control of an affected computer. IBM says the flaw, which was disclosed last week by Core Security Technologies, only affects the Lotus Notes client, and not the Domino server. A patch is available for Notes version 7 and 8.

    Sebastián Muñiz from the Core Impact Exploit Writers Team (EWT) at CorernSecurity Technologies is credited with discovering a buffer overflow vulnerability in a third-party file viewer that’s used to open Lotus 1-2-3 e-mail attachments. According to Core, the vulnerability in the Lotus WorkSheet file processor, which is developed by the software company Autonomy and which IBM distributes as a component of Notes, could allow an attacker to execute arbitrary code when they get a victim to open a corrupt Lotus 1-2-3 file sent as an e-mail attachment.

    IBM and Autonomy were alerted to the flaw, and worked together to develop a patch for Notes versions 7 and 8. Notes customers are encouraged to contact IBM to obtain the patch, according to IBM’s Technote on the problem.

    The problem also affects Notes versions 5 and 6. In lieu of a patch, users are encouraged to work around the flaw by disabling the Autonomy file viewer. Instructions on how to do this are available in the IBM Technote.

    The flaw represents a severe threat to organizations that use Lotus Notes for e-mail, says Core Security CTO Ivan Arce. “The discovery of this vulnerability in the Lotus Notes client underlines, once again, that securing endpoint systems and the applications that run on them is critical,” he says, “and that no vendor is immune to the perils of client application security.”



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    ARCAD Software

    Embrace VS Code for IBM i Development

    The IBM i development landscape is evolving with modern tools that enhance efficiency and collaboration. Ready to make the move to VS Code for IBM i?

    Join us for this webinar where we’ll showcase how VS Code can serve as a powerful editor for native IBM i code and explore the essential extensions that make it possible.

    In this session, you’ll discover:

    • How ARCAD’s integration with VS Code provides deep metadata insights, allowing developers to assess the impact of their changes upfront.
    • The role of Git in enabling seamless collaboration between developers using tools like SEU, RDi, and VS Code.
    • Powerful extensions for code quality, security, impact analysis, smart build, and automated RPG conversion to Free Form.
    • How non-IBM i developers can now contribute to IBM i projects without prior knowledge of its specifics, while ensuring full control over their changes.

    The future of IBM i development is here. Let ARCAD be your guide!

    Watch Now

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    DRV Technologies:  Automatically convert and distribute AS/400 reports with SpoolFlex
    Computer Measurement Group:  CMG '07 International Conference, December 2-7, San Diego
    COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee

    IT Jungle Store Top Book Picks

    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    SafeData Launches Telecom Recovery Service Utah Distributor Picks IBS for Supply Chain Management

    Leave a Reply Cancel reply

Volume 7, Number 45 -- December 4, 2007
THIS ISSUE SPONSORED BY:

LANSA
New Generation Software
Maximum Availability
Clearview Software International
Affirmative Computer

Table of Contents

  • Profound Logic Gives Web Access to DB2/400 with iData
  • Sametime, But a Different Place; IBM Tries to Top Microsoft
  • Touchtone Boosts Communication in i5/OS CRM
  • NGS Delivers Prebuilt BI for Healthcare
  • SafeData Launches Telecom Recovery Service
  • Patch Available for Lotus Notes Security Flaw
  • Utah Distributor Picks IBS for Supply Chain Management
  • Link Likes look for System i Modernization
  • New World Sells an i5/OS Solution–And 13 More for Windows
  • Calypso Sings Praise of Inovis for EDI

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Big Blue Is Still Talking About Future Power Processors, Which Is Good
  • Who To Consult With On Your Cloud Strategy, And Who To Manage It
  • Guru: DateTime Rules Of Thumb
  • i-Rays Performance Analyzer Now Ready for Prime Time, Omniology Says
  • CNX Adds AI To Valence Development Tool
  • Q&A With IBM’s New GM Of Power, Hillery Hunter
  • When IBM i Skills Become A Resilience Risk
  • Guru: Load A Varying-Dimension Array With One SQL Fetch
  • You Have To Speak IBM’s Language If You Want To Be Heard
  • Raz-Lee Revs iSecurity Suite With 2026 Updates

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle