Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
BID:4019
Info
Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
| Bugtraq ID: | 4019 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2002 12:00AM |
| Updated: | Feb 04 2002 12:00AM |
| Credit: | This issue was submitted to BugTraq on February 4th, 2002 by Peter Gründl <[email protected]>. |
| Vulnerable: |
Lotus Domino 5.0.9 Lotus Domino 5.0.8 Lotus Domino 5.0.7 a Lotus Domino 5.0.7 Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Domino 5.0.9 a |
Discussion
Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Windows and Unix.
It is possible to cause a denial of services to legitimate users of the web server. This is accomplished by invoking MS-DOS devices (such as CON, AUX, PRN, etc.) in multiple web requests.
A manual restart of the service is required to regain normal functionality.
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Windows and Unix.
It is possible to cause a denial of services to legitimate users of the web server. This is accomplished by invoking MS-DOS devices (such as CON, AUX, PRN, etc.) in multiple web requests.
A manual restart of the service is required to regain normal functionality.
Exploit / POC
Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
Solution:
This issue has been addressed in Lotus Domino 5.0.9a.
Lotus Domino 4.6.1
Lotus Domino 4.6.3
Lotus Domino 4.6.4
Lotus Domino 5.0
Lotus Domino 5.0.1
Lotus Domino 5.0.2
Lotus Domino 5.0.3
Lotus Domino 5.0.4
Lotus Domino 5.0.5
Lotus Domino 5.0.6
Lotus Domino 5.0.7
Lotus Domino 5.0.7 a
Lotus Domino 5.0.8
Lotus Domino 5.0.9
Solution:
This issue has been addressed in Lotus Domino 5.0.9a.
Lotus Domino 4.6.1
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 4.6.3
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 4.6.4
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.1
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.2
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.3
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.4
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.5
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.6
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.7
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.7 a
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.8
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.9
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
References
Lotus Domino MS-Dos Device Name Denial Of Service Vulnerability
References:
References: