{"vuid":"VU#676632","idnumber":"676632","name":"IBM Lotus Domino server mailbox name stack buffer overflow","keywords":["EMPHASISMINE","IMAP","Domino","CIMAPCommandStrArg::MailboxNameToLMBCS"],"overview":"The IBM Lotus Domino server  IMAP service contains a stack-based buffer overflow vulnerability in IMAP commands that refer to a mailbox name. This can allow a remote, authenticated attacker to execute arbitrary code with the privileges of the Domino server","clean_desc":"IBM Lotus Domino includes an IMAP server. This server contains a stack buffer overflow in the handling of mailbox names. By specifying a large mailbox name, an attacker can trigger a stack-based buffer overflow. Because IMAP commands that refer to a mailbox name are used after authentication, this vulnerability appears to only be exploitable by authenticated attackers. We have confirmed that this vulnerability affects Domino server 9.0.1FP8 and earlier versions. This exploit has been referred to by the \"EMPHASISMINE\" code name. Public exploit code uses the EXAMINE IMAP command, but other IMAP commands that refer to mailbox names may also be used. Note that on Windows at least one library used by Domino does not opt in to using ASLR, which makes exploitation trivial even on modern Windows platforms. This vulnerability is also exploitable when Domino is running on other platforms, such as Linux.","impact":"By sending a specially-crafted IMAP command that references a mailbox name to an affected server, a remote, authenticated attacker can execute arbitrary code on the Domino system with the privileges of the Domino IMAP server.","resolution":"Apply an update This issue is addressed in IBM Domino 9.0.1 Fix Pack 8 Interim Fix 2, and 8.5.3 Fix Pack 6 Interim Fix 17. Please see the IBM Security Bulletin for more details. Please also consider the following workarounds:","workarounds":"Use the Microsoft Enhanced Mitigation Experience Toolkit The Microsoft Enhanced Mitigation Experience Toolkit (EMET) can be used to help prevent exploitation of this and other vulnerabilities on the Windows platform.","sysaffected":"","thanks":"","author":"This document was written by Will Dormann.","public":["http://www-01.ibm.com/support/docview.wss?uid=swg22002280","https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-domino-server-imap-examine-command-stack-buffer-overflow-cve-2017-1274/","https://tools.ietf.org/html/rfc3501#section-6.3.2","https://support.microsoft.com/en-us/help/2458544/the-enhanced-mitigation-experience-toolkit"],"cveids":["CVE-2017-1274"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2017-04-17T19:08:06Z","publicdate":"2017-04-14T00:00:00Z","datefirstpublished":"2017-04-17T20:50:40Z","dateupdated":"2017-04-27T14:32:46Z","revision":44,"vrda_d1_directreport":"0","vrda_d1_population":"3","vrda_d1_impact":"4","cam_widelyknown":"0","cam_exploitation":"0","cam_internetinfrastructure":"0","cam_population":"0","cam_impact":"0","cam_easeofexploitation":"0","cam_attackeraccessrequired":"0","cam_scorecurrent":"0","cam_scorecurrentwidelyknown":"0","cam_scorecurrentwidelyknownexploited":"0","ipprotocol":"","cvss_accessvector":"N","cvss_accesscomplexity":"L","cvss_authentication":null,"cvss_confidentialityimpact":"C","cvss_integrityimpact":"C","cvss_availabilityimpact":"C","cvss_exploitablity":null,"cvss_remediationlevel":"ND","cvss_reportconfidence":"C","cvss_collateraldamagepotential":"ND","cvss_targetdistribution":"M","cvss_securityrequirementscr":"ND","cvss_securityrequirementsir":"ND","cvss_securityrequirementsar":"ND","cvss_basescore":"9","cvss_basevector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","cvss_temporalscore":"8.5","cvss_environmentalscore":"6.43574232","cvss_environmentalvector":"CDP:ND/TD:M/CR:ND/IR:ND/AR:ND","metric":0.0,"vulnote":null}