CVE-2008-2499

critical

Description

Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/42575

http://www.zerodayinitiative.com/advisories/ZDI-08-028/

http://www.vupen.com/english/advisories/2008/1595/references

http://www.securitytracker.com/id?1020093

http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21303920

http://secunia.com/advisories/30309

Details

Source: Mitre, NVD

Published: 2008-05-29

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical