PT-2003-1419 · Ibm · Lotus Domino Server

Mark Litchfield

·

Published

2003-03-29

·

Updated

2017-07-11

·

CVE-2003-0178

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Lotus Domino Web Server versions prior to 6.0.1
Description: The issue is related to multiple buffer overflows that can be triggered by remote attackers. This can be achieved through various means, including the s ViewName option and the Foldername option in the PresetFields parameter for iNotes, as well as a long Host header that is inserted into a long Location header during a redirect operation. These buffer overflows can cause a denial of service or allow the execution of arbitrary code.
Recommendations: For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the iNotes PresetFields parameter and limiting the length of the Host header to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0178

Affected Products

Lotus Domino Server