Lotus Domino HTTP Authentication Logging Buffer Overflow Vulnerability
BID:6646
Info
Lotus Domino HTTP Authentication Logging Buffer Overflow Vulnerability
| Bugtraq ID: | 6646 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1624 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2002 12:00AM |
| Updated: | Apr 04 2008 01:39AM |
| Credit: | Discovery of this issue is credited to The Relay Group. |
| Vulnerable: |
Lotus Domino 5.0.9 a Lotus Domino 5.0.9 Lotus Domino 5.0.8 Lotus Domino 5.0.7 a Lotus Domino 5.0.7 Lotus Domino 5.0.6 a Lotus Domino 5.0.6 Lotus Domino 5.0.5 Lotus Domino 5.0.4 a Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 |
| Not Vulnerable: |
Lotus Domino 5.0.10 |
Discussion
Lotus Domino HTTP Authentication Logging Buffer Overflow Vulnerability
Lotus Domino is prone to a remotely exploitable buffer-overflow condition. This issue occurs because of insufficient bounds-checking when HTTP Authentication data is logged to the 'DOMLOG.NSF' database. Remote attackers can corrupt sensitive regions of memory with attacker-supplied values, possibly allowing arbitrary code to run.
Lotus Domino is prone to a remotely exploitable buffer-overflow condition. This issue occurs because of insufficient bounds-checking when HTTP Authentication data is logged to the 'DOMLOG.NSF' database. Remote attackers can corrupt sensitive regions of memory with attacker-supplied values, possibly allowing arbitrary code to run.
References
Lotus Domino HTTP Authentication Logging Buffer Overflow Vulnerability
References:
References: