Lotus Domino Mail Loop Denial of Service Vulnerability
BID:3212
Info
Lotus Domino Mail Loop Denial of Service Vulnerability
| Bugtraq ID: | 3212 |
| Class: | Configuration Error |
| CVE: |
CVE-2000-1203 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Reported originally by SMILER <[email protected]> on March 22, 2000 and again by Ian Gulliver <[email protected]> on August 20, 2001. |
| Vulnerable: |
Lotus Domino 5.0.8 Lotus Domino 5.0.7 Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Domino 5.0.10 Lotus Domino 5.0.9 a Lotus Domino 5.0.9 |
Discussion
Lotus Domino Mail Loop Denial of Service Vulnerability
A potential denial of service vulnerability exists in some versions of Lotus Domino server.
The problem occurs when a message is received by the server with the mail recipient set as being at a domain that is not local to the server, and the sender as bounce@[127.0.0.1].
If this occurs, the server will attempt to bounce the message and will go into a bounce loop and consume all of the system's CPU, requiring that the server be restarted and the message be manually removed from the queue.
A potential denial of service vulnerability exists in some versions of Lotus Domino server.
The problem occurs when a message is received by the server with the mail recipient set as being at a domain that is not local to the server, and the sender as bounce@[127.0.0.1].
If this occurs, the server will attempt to bounce the message and will go into a bounce loop and consume all of the system's CPU, requiring that the server be restarted and the message be manually removed from the queue.
Solution / Fix
Lotus Domino Mail Loop Denial of Service Vulnerability
Solution:
This issue is fixed in Domino 5.0.9.
Solution:
This issue is fixed in Domino 5.0.9.
References
Lotus Domino Mail Loop Denial of Service Vulnerability
References:
References: