PT-2002-1173 · Ibm · Lotus Domino
Publicado
2002-03-07
·
Atualizado
2017-07-11
·
CVE-2002-0086
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Lotus Domino versions 5.0.4 through 5.0.7
Description
A buffer overflow issue exists in the bindsock component of Lotus Domino on Linux, allowing local users to escalate privileges to root. This can be achieved by manipulating either the
Notes ExecDirectory or PATH environment variables to be excessively long.Recommendations
For Lotus Domino version 5.0.4, update to a version that addresses this issue.
For Lotus Domino version 5.0.7, update to a version that addresses this issue.
As a temporary workaround, consider restricting the length of the
Notes ExecDirectory and PATH environment variables to prevent exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lotus Domino