SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#411489

Lotus Domino Web Retriever contains a buffer overflow vulnerability

Overview

A buffer overflow vulnerability may be exploited via the Lotus Domino Web Retriever. Versions prior to 5.0.12 and 6.0 are affected.

I. Description

According to the Rapid7 Advisory:

    The Lotus Notes/Domino Web Retriever task is responsible for retrieving web pages on behalf of Notes users who want to access the web via their Notes server.

    The Web Retriever program will crash when it receives an overly long HTTP status line from a remote web server.

    If the Web Retriever is running as a server task, the crash will cause a denial of service on the server.

    If the Web Retriever is running locally on a client, the crash will bring down the Notes client with it.

II. Impact

This vulnerability may be used to cause a denial of service.

III. Solution

Lotus has published a support document for this issue. Upgrade to version 5.0.12 or 6.0 Gold or 6.0.1.

In their support document, Lotus recommends disabling the WEB task on the server as a workaround. This task is not enabled by default.

Systems Affected

VendorStatusDate NotifiedDate Updated
LotusVulnerable13-Mar-2003

References


http://www.rapid7.com/advisories/R7-0011.html
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21105060

Credit

Thanks to Rapid7, Inc. Security Advisories and Lotus for reporting this vulnerability.

This document was written by Jason A Rafail based on information provided by Rapid7, Inc. and Lotus.

Other Information

Date Public:2003-03-06
Date First Published:2003-03-13
Date Last Updated:2003-03-18
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:12.66
Document Revision:17

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader