SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#555464

Lotus Domino vulnerable to DoS via many large connects sent to 63148/TCP

Overview

The Lotus Domino Web Server contains a flaw that could be exploited to cause a denial of service.

I. Description

A continuous stream of "connect" requests with a payload of 10K of data to TCP port 63148 (DIIOP - CORBA) will result in 100% CPU usage, the hard disk constantly being written to, and the memory slowly filling. The CPU usage will remain at 100% long after the attack is over.

II. Impact

Intruders can consume disk space, memory, and CPU cycles, possibly interrupting the normal operations of the Domino server.

III. Solution

Upgrade to Notes/Domino 5.0.7 or later. See http://www.notes.net/qmrdown.nsf/QMRWelcome.

Restrict access to port 63148 to trusted users if possible using a firewall or router. Change the default DIIOP listening port from 63148.

Systems Affected

VendorStatusDate NotifiedDate Updated
LotusVulnerable12-Jul-2001

References

VU#601312 VU#676552 VU#890128 VU#642760
http://www.securityfocus.com/bid/2599
http://www.securityfocus.com/advisories/3208
http://xforce.iss.net/static/6350.php
http://www.notes.net/r5fixlist.nsf/a8f0ffda1fc76c8985256752006aba6c/59719a1dd92c03e385256a4d0073766b?OpenDocument

Credit

Our thanks to Defcom Labs, which published an advisory on this and other problems, available at http://www.securityfocus.com/frames/?content=/templates/advisory.html?id=3208.

This document was written by Jason Rafail and is based on information obtained from a Defcom Labs Advisory.

Other Information

Date Public:2001-04-11
Date First Published:2001-07-12
Date Last Updated:2001-07-17
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Severity Metric:4.25
Document Revision:22

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2001 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader