|
|
|
![]() |
Vulnerability Note VU#355169Lotus Domino Web Server vulnerable to denial of service via incomplete POST requestOverviewLotus Domino Web Server is an application that provides access to Lotus Notes databases via HTTP requests. A vulnerability exists that could permit a remote attacker to cause a denial-of-service situation for HTTP requests.I. DescriptionLotus Domino Web Server contains a vulnerability in the nhttp.exe application that could permit a remote attacker to cause a denial-of-service situation when generating incomplete HTTP POST requests. This vulnerability was reportedly discovered using a Windows 2000 (SP3) machine running Domino Release 6.0.Further information is available in NGSSoftware advisory NISR17022003b and in IBM Technote 1104528 (SPR# KSPR5HTQHS). This vulnerability is addressed in Domino Releases 6.0.1 and 5.0.12.
There are no known workarounds for this vulnerability.
Referenceshttp://www.kb.cert.org/vuls/id/206361 Thanks to Mark Litchfield of NGS Software for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||