Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
BID:7038
Info
Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
| Bugtraq ID: | 7038 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0123 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery of this vulnerability credited to Rapid7, Inc. |
| Vulnerable: |
Lotus Notes Client 5.0.11 Lotus Notes Client 5.0.10 Lotus Notes Client 5.0.9 a Lotus Notes Client 5.0.5 Lotus Notes Client 5.0.4 Lotus Notes Client 5.0.3 Lotus Notes Client 5.0.2 Lotus Notes Client 5.0.1 Lotus Notes Client 5.0 Lotus Notes Client R5 Lotus Domino 5.0.11 Lotus Domino 5.0.10 Lotus Domino 5.0.9 a Lotus Domino 5.0.9 Lotus Domino 5.0.8 a Lotus Domino 5.0.8 -french Lotus Domino 5.0.8 Lotus Domino 5.0.7 a Lotus Domino 5.0.7 Lotus Domino 5.0.6 a Lotus Domino 5.0.6 Lotus Domino 5.0.5 -french Lotus Domino 5.0.5 Lotus Domino 5.0.4 a Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Notes Client 6.0.1 Lotus Notes Client 6.0 Lotus Notes Client R6 Lotus Domino 6.0.1 Lotus Domino 6.0 Lotus Domino 5.0.12 |
Discussion
Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
A buffer overflow vulnerability has been reported for the Web Retriever program that will result in a denial of service condition. Web Retriever is a program that returns web pages for Notes users.
An attacker can exploit this vulnerability by enticing a victim user to visit an attacker-controlled site. When a HTTP request is made, the malicious site responds with a HTTP response that includes an overly long status line. When Web Retriever processes this request, the buffer overflow condition is triggered and will result in a denial of service condition.
A buffer overflow vulnerability has been reported for the Web Retriever program that will result in a denial of service condition. Web Retriever is a program that returns web pages for Notes users.
An attacker can exploit this vulnerability by enticing a victim user to visit an attacker-controlled site. When a HTTP request is made, the malicious site responds with a HTTP response that includes an overly long status line. When Web Retriever processes this request, the buffer overflow condition is triggered and will result in a denial of service condition.
Exploit / POC
Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
Solution:
These issues have reportedly been fixed by upgrading to R5.0.12, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
Solution:
These issues have reportedly been fixed by upgrading to R5.0.12, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
References
Lotus Notes/Domino Web Retriever Buffer Overflow Denial Of Service Vulnerability
References:
References: