PT-2006-1200 · Ibm · Domino Server+1
Published
2006-01-09
·
Updated
2017-07-20
·
CVE-2006-0120
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
IBM Lotus Notes and Domino Server versions prior to 6.5.5
Description:
The issue involves multiple vectors that can cause a denial of service, resulting in an application crash. These vectors include sending a malformed message to an "Out Of Office" agent, using the compact command, processing malformed bitmap images, performing the "Delete Attachment" action, parsing certificates from a remote Certificate Table, and creating a SSL key ring with the Domino Administration client.
Recommendations:
For versions prior to 6.5.5, update to version 6.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Out Of Office" agent, limiting the use of the compact command, avoiding the processing of malformed bitmap images, restricting the "Delete Attachment" action, verifying the validity of certificates from remote Certificate Tables, and limiting the creation of SSL key rings with the Domino Administration client.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Domino Server
Ibm Lotus Notes