exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Zero Day Initiative Advisory 12-134 https://packetstormsecurity.com/files/115260/ZDI-12-134.txt https://packetstormsecurity.com/files/115260/ZDI-12-134.txt https://packetstormsecurity.com/files/115260/Zero-Day-Initiative-Advisory-12-134.html Fri, 03 Aug 2012 22:37:00 GMT Zero Day Initiative Advisory 12-134 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Quickr. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the QP2.cab ActiveX control. When passing a long string argument to the Attachment_Times or Import_Times parameters during the control's instantiation it is possible to overflow a stack buffer causing memory corruption. This can be leveraged by an attacker to execute code under the context of the user running the browser.

Related Files

No related files
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close