IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
BID:6951
Info
IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
| Bugtraq ID: | 6951 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0180 CVE-2003-0181 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery is credited to Mark Litchfield <[email protected]>. |
| Vulnerable: |
Lotus Domino 6.0 |
| Not Vulnerable: |
Lotus Domino 6.0.1 |
Discussion
IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
A denial of service vulnerability has been reported for Lotus Domino Server. The vulnerability occurs when the Lotus Domino Web server processes specially malformed HTTP POST requests.
The specially crafted POST requests will cause the Web server to behave in an unpredictable manner that may result in a denial of service condition.
A denial of service vulnerability has been reported for Lotus Domino Server. The vulnerability occurs when the Lotus Domino Web server processes specially malformed HTTP POST requests.
The specially crafted POST requests will cause the Web server to behave in an unpredictable manner that may result in a denial of service condition.
Exploit / POC
IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
Solution:
Administrators are advised to upgrade to Domino 6.0.1. The upgrades for various platforms are available at the following location:
Lotus Domino 6.0
Solution:
Administrators are advised to upgrade to Domino 6.0.1. The upgrades for various platforms are available at the following location:
Lotus Domino 6.0
-
IBM Lotus Domino 6.0.1 Upgrade
http://www14.software.ibm.com/webapp/download/search.jsp?q=&cat=&pf=&k =&dt=&go=y&rs=ESD-DMNTSRVRi&S_TACT=&S_CMP=&sb=r
References
IBM Lotus Domino Web Server HTTP POST Denial Of Service Vulnerability
References:
References:
- LOTUS DOMINO Denial Of Service Attacks 1 & 2 ("NGSSoftware Insight Security Research"
)