Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
BID:2575
Info
Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
| Bugtraq ID: | 2575 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2001 12:00AM |
| Updated: | Apr 11 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Peter Gründl <[email protected]> on April 11, 2001. |
| Vulnerable: |
Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 |
| Not Vulnerable: |
Lotus Domino 5.0.7 |
Discussion
Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
Lotus Domino R5 prior to version 5.0.7 is subject to a denial of service attack. If numerous requests are made for MS DOS device names, ncgihttp.exe inappropriately handles them, resulting in the exhaustion of system resources.
Lotus Domino R5 prior to version 5.0.7 is subject to a denial of service attack. If numerous requests are made for MS DOS device names, ncgihttp.exe inappropriately handles them, resulting in the exhaustion of system resources.
Exploit / POC
Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
Solution:
Lotus has rectified this issue in version 5.0.7:
http://www.notes.net/qmrdown.nsf/QMRWelcome
Solution:
Lotus has rectified this issue in version 5.0.7:
http://www.notes.net/qmrdown.nsf/QMRWelcome
References
Lotus Domino R5 Server MS-DOS Device DoS Vulnerability
References:
References: