Title : IBM Lotus Notes 1-2-3 File Viewer Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-4012 CVE ID : CVE-2007-6593
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-27
Technical Description
A vulnerability has been identified in IBM Lotus Notes, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the Lotus 1-2-3 file viewer (l123sr.dll) when processing a specially crafted ".123" file, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into double-clicking and viewing a specially crafted attachment.