IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
BID:29310
Info
IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
| Bugtraq ID: | 29310 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2240 |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2008 12:00AM |
| Updated: | Aug 25 2008 11:15PM |
| Credit: | M. Ruks, MWR InfoSecurity |
| Vulnerable: |
IBM Lotus Domino 7.0.3 IBM Lotus Domino 7.0 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0 IBM Lotus Domino 8.0 |
| Not Vulnerable: |
IBM Lotus Domino 8.0.1 IBM Lotus Domino 7.0.3 Fix Pack 1 (FP1) |
Discussion
IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
IBM Lotus Domino Server Web server is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application, which usually runs with LocalSystem privileges. Failed exploit attempts will result in a denial of service.
The issue affects IBM Lotus Domino 6.0, 6.5, 7.0, and 8.0.
IBM Lotus Domino Server Web server is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application, which usually runs with LocalSystem privileges. Failed exploit attempts will result in a denial of service.
The issue affects IBM Lotus Domino 6.0, 6.5, 7.0, and 8.0.
Exploit / POC
IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
The researchers who discovered this issue have developed a working exploit, but it is not publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The researchers who discovered this issue have developed a working exploit, but it is not publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
IBM Lotus Domino Web Server 'Accept Language' HTTP Header Buffer Overflow Vulnerability
References:
References:
- IBM Homepage (IBM)
- Lotus Domino Product Homepage (IBM)
- IBM Lotus Domino ?Accept-Language? Stack Overflow (MWR InfoSecurity)
- Lotus Domino Web server 'Accept-Language' stack overflow (IBM)