IBM Lotus Domino IMAP Quota Changing Vulnerability
BID:10642
Info
IBM Lotus Domino IMAP Quota Changing Vulnerability
| Bugtraq ID: | 10642 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0669 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Andreas Klein <[email protected]> reported this issue. |
| Vulnerable: |
IBM Lotus Domino 6.5.1 IBM Lotus Domino 6.5 .0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino IMAP Quota Changing Vulnerability
IBM Lotus Domino server is reported to improperly allow users to alter their own mail storage quota values.
A user's mailbox is assigned a quota to limit the amount of data that can be consumed by email on the server. This quota is assigned by the administrator of the application.
An attacker could possibly use this vulnerability to raise their mailbox's quota to a very large amount, and then proceed to fill the mail servers storage device. This will result in a denial of service condition, where new mail will not be able to be stored on the full disk.
Domino version 6.5.0 and 6.5.1 are reported vulnerable to this issue.
IBM Lotus Domino server is reported to improperly allow users to alter their own mail storage quota values.
A user's mailbox is assigned a quota to limit the amount of data that can be consumed by email on the server. This quota is assigned by the administrator of the application.
An attacker could possibly use this vulnerability to raise their mailbox's quota to a very large amount, and then proceed to fill the mail servers storage device. This will result in a denial of service condition, where new mail will not be able to be stored on the full disk.
Domino version 6.5.0 and 6.5.1 are reported vulnerable to this issue.
Exploit / POC
IBM Lotus Domino IMAP Quota Changing Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
IBM Lotus Domino IMAP Quota Changing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM Lotus Domino IMAP Quota Changing Vulnerability
References:
References:
- Lotus Domino Product Homepage (IBM)
- Unprevileged user can change quota on Domino (Andreas Klein
)