IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-013.txt | not applicable |
http://www.securityfocus.com/bid/26146 | vdb entry third party advisory broken link |
http://www.vupen.com/english/advisories/2007/3598 | vdb entry permissions required |
http://www-1.ibm.com/support/docview.wss?uid=swg21257030 | patch broken link |
http://secunia.com/advisories/27321 | broken link third party advisory patch vendor advisory |