Most Popular Stories
- Microsoft to give away free antivirus software
- IE market shares slip under 70 percent; Windows drops below 90 percent
- VMware reduces storage requirements of desktop VMs by 70 percent
- MySQL founder publicly criticizes MySQL 5.1
- New Windows worm builds massive botnet
- QUICKLINKS: Cisco and Apple talking again; IBM comes on-board for WiMAX; Broadcom releases chip with FM, WiFi and Bluetooth
- U.S. military bans USB flash drives and removable media
- Analyst: Apple will launch netbook competitor in response to slowdown
- Report claims that Google is snipping 10,000 jobs
- CMS Watch says enterprise search vendors are opening up
- Hard times attract cybercrime boom
- Using text messages to remotely disable Lenovo ThinkPads
Events
Sponsored Links
Latest News
Popular Topics
Whitepapers
- The Definitive IP Address Management (IPAM) Intelligence Whitepaper
- HIPAA Security Provisions
- Service Oriented Architecture
- How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
- Collaboration and Social Media: Taking Stock of Today's Experiences and Tomorrow's Opportunities
- IM and Presence: Achieving Mission Critical Status in the Enterprise
Lotus Notes catches a bug
Lotus Notes has a new headache. Researchers at Core Security Technologies say there is a serious bug in the Autonomy KeyView software used by Lotus Notes to process Lotus 1-2-3 files. Ivan Arce, Core's chief technology officer, says it would not be hard for an attacker to write the code that provides passage into the software. "Previously there have been other flaws like this published for the same software development kit," Arce said. "So anyone keeping track of that could write an exploit pretty quickly."
When Core researchers opened a specially-crafted Lotus 1-2-3 email attachment in Lotus Notes, they found they could run unauthorized software on the PC. This kind of vulnerability is not new, however--it's a kind of flaw called a "file parsing bug." However, there have been improvements in stopping attacks that take advantage of such bugs, which are called "fuzzers." They send a barrage of data to programs in order to see if they can be made to act in unexpected ways.
IBM disclosed this problem in a Nov. 26 security alert, and the company is offering a software patch for Notes 7 users. For those using an older version of Notes, IBM has suggested several workarounds, including deleting the Windows DLL (dynamic link library) file that is associated with Notes.
For more on this software bug:
- See this ComputerWorld article
Related Stories
- UCLA making databases less sensitive, more secure
- Is your VoIP network secure?
- Spam turns 30
- Watch out for your IT security scorecard
- ATM machines cry out for security
- Crossing the border gets tougher
- How hard is it to secure your data?
- Security woes dog Microsoft
- Data loss costs a bundle
- Identy theft is not cheap
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





