PT-2002-1173 · Ibm · Lotus Domino
Published
2002-03-07
·
Updated
2017-07-11
·
CVE-2002-0086
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Lotus Domino versions 5.0.4 through 5.0.7
Description
A buffer overflow issue exists in the bindsock component of Lotus Domino on Linux, allowing local users to escalate privileges to root. This can be achieved by manipulating either the
Notes ExecDirectory or PATH environment variables to be excessively long.Recommendations
For Lotus Domino version 5.0.4, update to a version that addresses this issue.
For Lotus Domino version 5.0.7, update to a version that addresses this issue.
As a temporary workaround, consider restricting the length of the
Notes ExecDirectory and PATH environment variables to prevent exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lotus Domino