Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://secunia.com/advisories/43208 | third party advisory |
http://zerodayinitiative.com/advisories/ZDI-11-052/ | |
http://www-01.ibm.com/support/docview.wss?uid=swg21461514 | vendor advisory |