Lotus Domino R5 Server HTTP DoS Vulnerability
BID:2598
Info
Lotus Domino R5 Server HTTP DoS Vulnerability
| Bugtraq ID: | 2598 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2001 12:00AM |
| Updated: | Apr 11 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on April 11, 2001. |
| Vulnerable: |
Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 |
| Not Vulnerable: |
Lotus Domino 5.0.7 |
Discussion
Lotus Domino R5 Server HTTP DoS Vulnerability
An exploitable denial of service condition exists in Lotus Domino R5 Server. An HTTP request composed of numerous '/' sequences (approx 8k), will cause the server to consume all available system resources on the host.
An exploitable denial of service condition exists in Lotus Domino R5 Server. An HTTP request composed of numerous '/' sequences (approx 8k), will cause the server to consume all available system resources on the host.
Exploit / POC
Lotus Domino R5 Server HTTP DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lotus Domino R5 Server HTTP DoS Vulnerability
Solution:
Lotus has addressed this issue in version 5.0.7:
http://www.notes.net/qmrdown.nsf/QMRWelcome
Solution:
Lotus has addressed this issue in version 5.0.7:
http://www.notes.net/qmrdown.nsf/QMRWelcome