PT-2002-1173 · Ibm · Lotus Domino

Publicado

2002-03-07

·

Atualizado

2017-07-11

·

CVE-2002-0086

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lotus Domino versions 5.0.4 through 5.0.7
Description A buffer overflow issue exists in the bindsock component of Lotus Domino on Linux, allowing local users to escalate privileges to root. This can be achieved by manipulating either the Notes ExecDirectory or PATH environment variables to be excessively long.
Recommendations For Lotus Domino version 5.0.4, update to a version that addresses this issue. For Lotus Domino version 5.0.7, update to a version that addresses this issue. As a temporary workaround, consider restricting the length of the Notes ExecDirectory and PATH environment variables to prevent exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0086

Produtos afetados

Lotus Domino