Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Reply to this topicStart new topic
> IBM Lotus Notes advisories/updates
AplusWebMaster
post Oct 23 2007, 09:33 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,667
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://secunia.com/advisories/27279/
Release Date: 2007-10-23
Critical: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Notes 6.x, IBM Lotus Notes 7.x ...
Solution: Update to version 7.0.3 or 8.0.
NOTE: Version 8.0 does not fix the vulnerability in wp6sr.dll.
http://www-306.ibm.com/software/lotus/supp...tral/index.html ...

http://www-1.ibm.com/support/docview.wss?uid=swg21271111
"...Fixed in Lotus Notes 7.0.3 / Proposed for 8.0.1..."

.

This post has been edited by AplusWebMaster: Jun 7 2008, 03:57 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Nov 27 2007, 09:33 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,667
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

IBM Lotus Notes Lotus 1-2-3 vuln - patch available
- http://secunia.com/advisories/27835/
Release Date: 2007-11-27
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Notes 7.x, IBM Lotus Notes 8.x
...The vulnerability is reported in versions 7.0 and 8.0.
Solution: Lotes Notes 7.x/8.x: Contact IBM Support for patches.
Original Advisory: IBM:
http://www-1.ibm.com/support/docview.wss?uid=swg21285600

.
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Feb 20 2008, 06:57 AM
Post #3


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,667
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

IBM Lotus Notes Java vuln - workaround available
- http://secunia.com/advisories/29035/
Release Date: 2008-02-20
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Workaround
Software: IBM Lotus Notes 6.x, IBM Lotus Notes 7.x
...The vulnerability is reported in versions 6.5.6 and 7.0.
Solution: Version 7.0.2 reportedly includes the JVM fix. The vendor recommends disabling "Enable Java access from JavaScript"...
Original Advisory:
http://www-1.ibm.com/support/docview.wss?uid=swg21257249

Also see:
- http://secunia.com/advisories/29031/
Release Date: 2008-02-20
Critical: Less critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Workaround
Software: IBM Lotus Notes 6.x, IBM Lotus Notes 7.x, IBM Lotus Notes 8.x
Original Advisory:
http://www-1.ibm.com/support/docview.wss?uid=swg21257250

ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post May 27 2008, 03:55 AM
Post #4


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,667
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://secunia.com/advisories/30309/
Release Date: 2008-05-22
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Sametime 7.x, IBM Lotus Sametime 8.x
...Successful exploitation may allow execution of arbitrary code.
Solution: Update to version 8.0.1 or apply hotfix ICAE-7DPP83 for Lotus Sametime 7.5.1 Cumulative Fix 1 (CF1). Contact IBM support for the patch if Sametime 7.5.1 CF1 is not deployed or if unable to update to 8.0.1.
http://preview.tinyurl.com/5s6mz9
Original Advisory:
IBM: http://www-1.ibm.com/support/docview.wss?uid=swg21303920

- http://www.us-cert.gov/current/#ibm_lotus_...e_vulnerability
May 22, 2008

- http://isc.sans.org/diary.html?storyid=4460
Last Updated: 2008-05-26 23:54:12 UTC - "Take a look at port 1533*. That's quite an increase in targeted computers reporting via DShield over the past few days..."

* http://isc.sans.org/port.html?port=1533
"...tcp 1533 used by Lotus Sametime for chat and awareness..."
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts  
9 akmahey 46 Today, 10:47 AM
Last post by: Tomk
No new
21 AplusWebMaster 1,626 Today, 07:35 AM
Last post by: AplusWebMaster
No new
116 AplusWebMaster 16,316 Yesterday, 11:02 PM
Last post by: AplusWebMaster
No New Posts
11 AplusWebMaster 1,229 8th October 2008 - 07:05 PM
Last post by: AplusWebMaster
No New Posts
0 AplusWebMaster 4 7th October 2008 - 02:15 PM
Last post by: AplusWebMaster

RSS Time is now: 10th October 2008 - 05:20 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy