Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

Lotus Notes buffer overflow in the Lotus WorkSheet file processor, (Tue, Nov 27th)

Security News




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 11-27-2007
Steve's Avatar
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 57,504
Steve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to behold
Thanks: 11
Thanked 92 Times in 21 Posts
Lotus Notes buffer overflow in the Lotus WorkSheet file processor, (Tue, Nov 27th)
Core Security has put out a new advisory concerning a buffer overflow in Lotus Notes. Both remotely and locally exploitable.
Core lists the vulnerable software pieces as:
- Lotus Notes version 7.x

- Lotus Notes version 8.x (not confirmed by Core)

- Lotus Notes version 6.5.6 (not confirmed by Core)

- Other software packages using Verity KeyView SDK using vulnerable

versions of l123sr.dll
Although it's prudent to keep in mind that as of now 8.x and 6.5.6 are NOT confirmed by Core (as in their advisory, and the cut and paste above).
Cut and Paste from Core's Advisory:
Lotus Notes customers should follow the instructions of the following

support Technote, which outlines the available options based on specific

versions of Lotus Notes:



http://www.ibm.com/support/docview.w...id=swg21285600



Workaround 1: Delete the keyview.ini file in the Notes program directory.

This disables ALL viewers. When a user clicks View (for any file), a

dialog box will display with the message Unable to locate the viewer

configuration file..



Workaround 2: Delete the problem file l123sr.dll file. When a user tries

to view the specific file type, a dialog box will display with the message

The viewer display window could not be initialized.). When a user tries to view the specific file type, a dialog

box will display with the message The viewer display window could not be

initialized81.2.0.9.0=l123sr.dll



Workaround 4: Filter inbound emails with attachments with potentially

malicious files. Lotus 1-2-3 files are usually associated to MIME

Content-Type headers set to the following strings:

application/lotus-1-2-3

application/lotus123

application/x-lotus123

application/wks

application/x-wks

application/vnd.lotus-1-2-3

Note however that workaround #4 is a simply stop gap measure that could be

circumvented by relatively unsophisticated attackers.

Joel Esler
http://www.joelesler.net

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Unistal Lotus Notes to Outlook Conversion 1.0 VistaUtils Vista Utilities Feed 0 10-19-2007 12:30
Can the mails from Lotus notes be imported? Shashidhar Hegde microsoft.public.windows.vista.mail 1 10-02-2007 02:05
Vista Search and Lotus Notes iFilter Per Hellberg microsoft.public.windows.vista.file management 0 10-01-2007 20:56
Windows Vista doesn't work with Lotus Notes HamedNYC microsoft.public.windows.vista.installation setup 4 06-24-2007 14:20
vista and client lotus notes =?Utf-8?B?QW5kcmVqIMWga29yxYhh?= microsoft.public.windows.vista.mail 4 01-23-2007 14:41




All times are GMT +1. The time now is 11:27.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119