Lotus Domino SunRPC Denial of Service Vulnerability
BID:3607
Info
Lotus Domino SunRPC Denial of Service Vulnerability
| Bugtraq ID: | 3607 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2001 12:00AM |
| Updated: | Nov 30 2001 12:00AM |
| Credit: | Discovered by Ninke Westra and posted to the BugTraq mailing list on November 30, 2001 by "Hendrik-Jan Verheij" <[email protected]>. |
| Vulnerable: |
Lotus Domino 5.0.8 Lotus Domino 5.0.7 Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 |
| Not Vulnerable: |
Lotus Domino 5.0.9 |
Discussion
Lotus Domino SunRPC Denial of Service Vulnerability
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms, and includes support for the popular Lotus Notes client software.
When Lotus Domino receives a SunRPC NULL command on port 443, the nhttp process crashes, effecting a DoS attack on the Domino server. The process must be restarted to regain normal functionality.
This affects Domino servers with the http task running and ssl enabled.
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms, and includes support for the popular Lotus Notes client software.
When Lotus Domino receives a SunRPC NULL command on port 443, the nhttp process crashes, effecting a DoS attack on the Domino server. The process must be restarted to regain normal functionality.
This affects Domino servers with the http task running and ssl enabled.
Exploit / POC
Lotus Domino SunRPC Denial of Service Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Lotus Domino SunRPC Denial of Service Vulnerability
Solution:
Lotus has offered an updated version, 5.0.9, which is no longer vulnerable to this attack.
Lotus Domino 5.0
Lotus Domino 5.0.1
Lotus Domino 5.0.2
Lotus Domino 5.0.3
Lotus Domino 5.0.4
Lotus Domino 5.0.5
Lotus Domino 5.0.6
Lotus Domino 5.0.7
Lotus Domino 5.0.8
Solution:
Lotus has offered an updated version, 5.0.9, which is no longer vulnerable to this attack.
Lotus Domino 5.0
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.1
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.2
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.3
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.4
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.5
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.6
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.7
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome
Lotus Domino 5.0.8
-
Lotus Domino R5.0.9
http://www.notes.net/qmrdown.nsf/qmrwelcome