Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
BID:4020
Info
Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
| Bugtraq ID: | 4020 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2002 12:00AM |
| Updated: | Feb 04 2002 12:00AM |
| Credit: | This vulnerability was discovered by Peter Gründl <[email protected]>. |
| Vulnerable: |
Lotus Domino 5.0.9 Lotus Domino 5.0.8 Lotus Domino 5.0.7 Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Domino 5.0.9 a |
Discussion
Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
Lotus Domino Server is an application framework for web based
collaborative software. It runs on multiple platforms including Windows
and Unix.
It has been reported that all versions of Lotus Domino Webserver prior to 5.0.9a running on Windows 2000 may be vulnerable to a denial of service condition.
If a request for a DOS device from CGI-BIN has an extension of 220 characters, the server will spawn a cmd.exe session to run nul.pif. The server will also pop up a window asking for a program association to run nul.pif with. If this is done approximately 400 times, the server will reportedly run out of working threads.
This vulnerability may not having anything to do with the inclusion of MS-DOS device names in requests, but this is unconfirmed.
Lotus Domino Server is an application framework for web based
collaborative software. It runs on multiple platforms including Windows
and Unix.
It has been reported that all versions of Lotus Domino Webserver prior to 5.0.9a running on Windows 2000 may be vulnerable to a denial of service condition.
If a request for a DOS device from CGI-BIN has an extension of 220 characters, the server will spawn a cmd.exe session to run nul.pif. The server will also pop up a window asking for a program association to run nul.pif with. If this is done approximately 400 times, the server will reportedly run out of working threads.
This vulnerability may not having anything to do with the inclusion of MS-DOS device names in requests, but this is unconfirmed.
Exploit / POC
Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
There is no exploit code required for this vulnerability.
There is no exploit code required for this vulnerability.
Solution / Fix
Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
Solution:
The vendor has corrected the issue in Lotus Domino 5.0.9a.
Lotus Domino 4.6.1
Lotus Domino 4.6.3
Lotus Domino 4.6.4
Lotus Domino 5.0
Lotus Domino 5.0.1
Lotus Domino 5.0.2
Lotus Domino 5.0.3
Lotus Domino 5.0.4
Lotus Domino 5.0.5
Lotus Domino 5.0.6
Lotus Domino 5.0.7
Lotus Domino 5.0.8
Lotus Domino 5.0.9
Solution:
The vendor has corrected the issue in Lotus Domino 5.0.9a.
Lotus Domino 4.6.1
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 4.6.3
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 4.6.4
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.1
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.2
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.3
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.4
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.5
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.6
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.7
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.8
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
Lotus Domino 5.0.9
-
Lotus Domino 5.0.9a
http://notes.net/qmrdown.nsf
References
Lotus Domino Webserver DOS Device Extension Denial of Service Vulnerability
References:
References: