|
|
|
![]() |
Vulnerability Note VU#772563Lotus Domino web server vulnerable to buffer overflow via long HTTP authentication header containing non-ASCII charactersOverviewA remotely exploitable buffer overflow exists in versions of IBM's Lotus Domino web server prior to R5.0.10.I. DescriptionA remotely exploitable buffer overflow exists in the Lotus Domino web server. The overflow can occur as the result of an overly long HTTP Authenticate header containing certain non-ASCII characters. For more information, please see the IBM Technote.II. ImpactAn intruder can execute arbitrary code with the privileges of the Lotus Domino web server.III. SolutionUpgrade to R5.0.10 or later.Workaround
References
This vulnerability was discovered by The Relay Group. This document was written by Ian A. Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||