PT-2003-1419 · Ibm · Lotus Domino Server
Mark Litchfield
·
Publicado
2003-03-29
·
Atualizado
2017-07-11
·
CVE-2003-0178
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Lotus Domino Web Server versions prior to 6.0.1
Description:
The issue is related to multiple buffer overflows that can be triggered by remote attackers. This can be achieved through various means, including the
s ViewName option and the Foldername option in the PresetFields parameter for iNotes, as well as a long Host header that is inserted into a long Location header during a redirect operation. These buffer overflows can cause a denial of service or allow the execution of arbitrary code.Recommendations:
For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the iNotes
PresetFields parameter and limiting the length of the Host header to prevent exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lotus Domino Server