PT-2002-1173 · Ibm · Lotus Domino

Published

2002-03-07

·

Updated

2017-07-11

·

CVE-2002-0086

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lotus Domino versions 5.0.4 through 5.0.7
Description A buffer overflow issue exists in the bindsock component of Lotus Domino on Linux, allowing local users to escalate privileges to root. This can be achieved by manipulating either the Notes ExecDirectory or PATH environment variables to be excessively long.
Recommendations For Lotus Domino version 5.0.4, update to a version that addresses this issue. For Lotus Domino version 5.0.7, update to a version that addresses this issue. As a temporary workaround, consider restricting the length of the Notes ExecDirectory and PATH environment variables to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0086

Affected Products

Lotus Domino