PT-2003-1419 · Ibm · Lotus Domino Server

Mark Litchfield

·

Publicado

2003-03-29

·

Atualizado

2017-07-11

·

CVE-2003-0178

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Lotus Domino Web Server versions prior to 6.0.1
Description: The issue is related to multiple buffer overflows that can be triggered by remote attackers. This can be achieved through various means, including the s ViewName option and the Foldername option in the PresetFields parameter for iNotes, as well as a long Host header that is inserted into a long Location header during a redirect operation. These buffer overflows can cause a denial of service or allow the execution of arbitrary code.
Recommendations: For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the iNotes PresetFields parameter and limiting the length of the Host header to prevent exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0178

Produtos afetados

Lotus Domino Server