Lotus Domino MS-DOS Device Path Disclosure Vulnerability
BID:4406
Info
Lotus Domino MS-DOS Device Path Disclosure Vulnerability
| Bugtraq ID: | 4406 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0407 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to Peter Gründl <[email protected]>. |
| Vulnerable: |
Lotus Domino 5.0.9 a |
| Not Vulnerable: |
Lotus Domino 5.0.10 |
Discussion
Lotus Domino MS-DOS Device Path Disclosure Vulnerability
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Microsoft Windows and Unix.
Vulnerable versions of Lotus Domino do not properly handle specially crafted requests for MS-DOS devices, causing sensitive path information to be disclosed to remote attackers.
Sensitive information gathered in this manner may aid the attacker in further attacks against the host running the vulnerable software.
This issue was reported for Lotus Domino v5.0.9a for Microsoft Windows platforms. Earlier versions may also be affected.
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Microsoft Windows and Unix.
Vulnerable versions of Lotus Domino do not properly handle specially crafted requests for MS-DOS devices, causing sensitive path information to be disclosed to remote attackers.
Sensitive information gathered in this manner may aid the attacker in further attacks against the host running the vulnerable software.
This issue was reported for Lotus Domino v5.0.9a for Microsoft Windows platforms. Earlier versions may also be affected.
Exploit / POC
Lotus Domino MS-DOS Device Path Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Lotus Domino MS-DOS Device Path Disclosure Vulnerability
Solution:
This issue has been addressed in v5.0.10 of Lotus Domino. Administrators are advised to upgrade.
Lotus Domino 5.0.9 a
Solution:
This issue has been addressed in v5.0.10 of Lotus Domino. Administrators are advised to upgrade.
Lotus Domino 5.0.9 a
-
IBM Lotus Domino 5.0.10
http://www.notes.net/qmrdown.nsf
References
Lotus Domino MS-DOS Device Path Disclosure Vulnerability
References:
References: