CVE-2014-0892

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:lotus_domino:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:9.0.1.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:ibm:lotus_notes:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:8.5.3.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:9.0.1.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://www-01.ibm.com/support/docview.wss?uid=swg21670264 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21670264 - Vendor Advisory
References () http://www.kb.cert.org/vuls/id/350089 - US Government Resource () http://www.kb.cert.org/vuls/id/350089 - US Government Resource
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/91286 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/91286 -

Information

Published : 2014-04-23 19:55

Updated : 2024-11-21 02:02


NVD link : CVE-2014-0892

Mitre link : CVE-2014-0892

CVE.ORG link : CVE-2014-0892


JSON object : View

Products Affected

ibm

  • lotus_domino
  • lotus_notes

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor