Rare bug blights Lotus Notes
1-2-3 hack risk
Posted in Enterprise Security, 28th November 2007 10:39 GMT
Webcast: Building Applications for the 21st Century
Security researchers have discovered a rare, and potentially serious, security bug in Lotus Notes. A buffer overflow flaw in IBM's groupware package enables hackers to trick users into running hostile code on vulnerable systems.
The security bug stems from boundary errors within the Lotus 1-2-3 file viewer (l123sr.dll) component. Successful exploitation of the bug involves tricking users into viewing maliciously crafted Lotus 1-2-3 attachments, designed to allow the execution of arbitrary code on vulnerable systems.
The flaws, discovered by security researchers with Core Security, affect versions 7.x and 8.x of Lotus Notes. Other versions may also be affected.
Sys admins are advised to contact IBM support for patches, as explained here. ®

The Register Guide to Extended Validation
LDAP Injection [3-2APZ1KL]
Preventing Google Hacking [3-2APYMGU]
Web application security [3-2APYM3X]
Building Web Application Security into Your Development Process [3-2APYMBV]

Inmate hacked prison network, broke into employee database
Miscreants hijacking machines via (freshly patched) Adobe flaw
Martial law planned for Craigslist's red-light district
Cocaine addicted IT manager hacks ex-employer's mail servers