Vulnerability Note VU#411489
Lotus Domino Web Retriever contains a buffer overflow vulnerability
Overview
A buffer overflow vulnerability may be exploited via the Lotus Domino Web Retriever. Versions prior to 5.0.12 and 6.0 are affected.
Description
According to the Rapid7 Advisory: The Lotus Notes/Domino Web Retriever task is responsible for retrieving web pages on behalf of Notes users who want to access the web via their Notes server. |
Impact
This vulnerability may be used to cause a denial of service. |
Solution
Lotus has published a support document for this issue. Upgrade to version 5.0.12 or 6.0 Gold or 6.0.1. |
In their support document, Lotus recommends disabling the WEB task on the server as a workaround. This task is not enabled by default. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Lotus | Affected | - | 13 Mar 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.rapid7.com/advisories/R7-0011.html
- http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21105060
Credit
Thanks to Rapid7, Inc. Security Advisories and Lotus for reporting this vulnerability.
This document was written by Jason A Rafail based on information provided by Rapid7, Inc. and Lotus.
Other Information
- CVE IDs: Unknown
- Date Public: 06 Mar 2003
- Date First Published: 13 Mar 2003
- Date Last Updated: 18 Mar 2003
- Severity Metric: 12.66
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.