IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
BID:7037
Info
IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
| Bugtraq ID: | 7037 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0122 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery of this vulnerability credited to Rapid7, Inc. |
| Vulnerable: |
Lotus Notes Client 5.0.11 Lotus Notes Client 5.0.10 Lotus Notes Client 5.0.9 a Lotus Notes Client 5.0.5 Lotus Notes Client 5.0.4 Lotus Notes Client 5.0.3 Lotus Notes Client 5.0.2 Lotus Notes Client 5.0.1 Lotus Notes Client 5.0 Lotus Notes Client R5 Lotus Domino 5.0.11 Lotus Domino 5.0.10 Lotus Domino 5.0.9 a Lotus Domino 5.0.9 Lotus Domino 5.0.8 a Lotus Domino 5.0.8 -french Lotus Domino 5.0.8 Lotus Domino 5.0.7 a Lotus Domino 5.0.7 Lotus Domino 5.0.6 a Lotus Domino 5.0.6 Lotus Domino 5.0.5 -french Lotus Domino 5.0.5 Lotus Domino 5.0.4 a Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Notes Client 6.0.1 Lotus Notes Client 6.0 Lotus Notes Client R6 Lotus Domino 6.0.1 Lotus Domino 6.0 Lotus Domino 5.0.12 IBM Lotus Notes 6.0.1 IBM Lotus Notes 6.0 IBM Lotus Notes 5.0.12 |
Discussion
IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
A heap corruption vulnerability has been reported for Lotus Notes and Lotus Domino. The vulnerability exists in the NotesRPC authentication protocol used by Notes clients and servers.
When authenticating against a Notes server, a client sends data regarding its DN. Manipulation of some header fields in the data packets sent to the Notes server will trigger an arithmetic error which will result in the corruption of heap memory.
An unauthenticated Notes client can exploit this vulnerability by connecting to a vulnerable Notes server and manipulating the contents of the data that is being exchanged with the server. This will trigger the overflow condition and will result in the corruption of sensitive heap memory with attacker-supplied values and lead to a denial of service condition.
This issue was originally described in BID 7036. It is now being assigned its own BID.
A heap corruption vulnerability has been reported for Lotus Notes and Lotus Domino. The vulnerability exists in the NotesRPC authentication protocol used by Notes clients and servers.
When authenticating against a Notes server, a client sends data regarding its DN. Manipulation of some header fields in the data packets sent to the Notes server will trigger an arithmetic error which will result in the corruption of heap memory.
An unauthenticated Notes client can exploit this vulnerability by connecting to a vulnerable Notes server and manipulating the contents of the data that is being exchanged with the server. This will trigger the overflow condition and will result in the corruption of sensitive heap memory with attacker-supplied values and lead to a denial of service condition.
This issue was originally described in BID 7036. It is now being assigned its own BID.
Exploit / POC
IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
Solution:
These issues have reportedly been fixed by upgrading to R5.0.12, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
Solution:
These issues have reportedly been fixed by upgrading to R5.0.12, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
References
IBM Lotus Notes Protocol Authentication Heap Corruption Denial Of Service Vulnerability
References:
References: