Vulnerability Note VU#206361
Lotus iNotes vulnerable to buffer overflow via PresetFields FolderName field
Overview
Lotus iNotes contains a buffer overflow that could permit a remote attacker to execute arbitrary code or cause a denial of service on a vulnerable server.
Description
Lotus iNotes Web Access is a database application that provides "access to corporate messaging services and personal information through a Web browser." NGSSoftware has researched and reported a buffer overflow vulnerability in iNotes that can be triggered via a specially crafted FolderName value of the PresetFields parameter. For further information, see NGSSoftware Insight Security Research Advisory #NISR17022003b. Lotus is tracking this issue as SPR# KSPR5HUQ59. Further information is available in IBM Technote 1104527. |
Impact
A remote attacker could execute arbitrary code with the privileges of the Domino server process or cause a denial of service. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Lotus Software | Affected | 17 Jan 2003 | 17 Mar 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.lotus.com/products/inotes.nsf
- http://www.lotus.com/products/inotes.nsf/allpublic/53380DDF183DC9A38525697C006E652E?opendocument
- http://www.nextgenss.com/advisories/lotus-inotesoflow.txt
- http://www-1.ibm.com/support/docview.wss?uid=swg21104527
- http://www-1.ibm.com/support/docview.wss?uid=swg27003694
- http://www-10.lotus.com/ldd/r5fixlist.nsf/a8f0ffda1fc76c8985256752006aba6c/fcd56eb247bf688085256cca0070f90c?OpenDocument
Credit
This vulnerability was reported by Mark Litchfield of NGSSoftware.
This document was written by Art Manion.
Other Information
- CVE IDs: Unknown
- CERT Advisory: CA-2003-11
- Date Public: 17 Feb 2003
- Date First Published: 19 Feb 2003
- Date Last Updated: 26 Mar 2003
- Severity Metric: 18.51
- Document Revision: 25
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.