PT-2003-1419 · Ibm · Lotus Domino Server
Mark Litchfield
·
Published
2003-03-29
·
Updated
2017-07-11
·
CVE-2003-0178
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Lotus Domino Web Server versions prior to 6.0.1
Description:
The issue is related to multiple buffer overflows that can be triggered by remote attackers. This can be achieved through various means, including the
s ViewName option and the Foldername option in the PresetFields parameter for iNotes, as well as a long Host header that is inserted into a long Location header during a redirect operation. These buffer overflows can cause a denial of service or allow the execution of arbitrary code.Recommendations:
For versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the iNotes
PresetFields parameter and limiting the length of the Host header to prevent exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lotus Domino Server