IBM has issued a security bulletin to address two GIF parsing buffer overflow vulnerabilities in IBM Domino. A remote attacker could exploit these vulnerabilities by sending a specially crafted GIF image in email to a vulnerable Domino SMTP server.
Successful exploitation could lead to arbitrary code execution and system crash.
The vendor has released fixes to address the issues and they can be downloaded at the following URL:
http://www-01.ibm.com/support/docview.wss?uid=swg21969050
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4994
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5040