Lotus Domino bindsock PATH Buffer Overflow Vulnerability
BID:4319
Info
Lotus Domino bindsock PATH Buffer Overflow Vulnerability
| Bugtraq ID: | 4319 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0086 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 15 2001 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery credited to Kevin Kotas of the eSecurityOnline Research and Development Team. |
| Vulnerable: |
Lotus Domino 5.0.9 Lotus Domino 5.0.8 -french Lotus Domino 5.0.8 Lotus Domino 5.0.7 a Lotus Domino 5.0.7 Lotus Domino 5.0.6 a Lotus Domino 5.0.6 Lotus Domino 5.0.5 -french Lotus Domino 5.0.5 Lotus Domino 5.0.4 a Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 |
| Not Vulnerable: |
Lotus Domino 5.0.9 a |
Discussion
Lotus Domino bindsock PATH Buffer Overflow Vulnerability
Lotus Domino is a high performance collection of applications based on messaging, collaboration, scheduling and calendaring. Domino is available on a wide range of platforms, including Linux, Windows, AS/400 and many Unix based systems.
Lotus Domino for UNIX systems ships with a setuid root utility called 'bindsock'.
This program contains a locally exploitable buffer overflow condition related to handling of the PATH environment variable. It is reportedly possible for a local user to elevate privileges if this vulnerability is successfully exploited.
Lotus Domino is a high performance collection of applications based on messaging, collaboration, scheduling and calendaring. Domino is available on a wide range of platforms, including Linux, Windows, AS/400 and many Unix based systems.
Lotus Domino for UNIX systems ships with a setuid root utility called 'bindsock'.
This program contains a locally exploitable buffer overflow condition related to handling of the PATH environment variable. It is reportedly possible for a local user to elevate privileges if this vulnerability is successfully exploited.