Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain a shell remotely >> Lotus Domino Server Date Fields Overflow Vulnerability


Vulnerability Assessment Details

Lotus Domino Server Date Fields Overflow Vulnerability

Vulnerability Assessment Summary
Checks for date fields overflow vulnerability in Lotus Domino Server

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server is susceptible to a buffer overflow
vulnerability.

Description :

According to its banner, the remote host is running a version of Lotus
Domino Server that is prone to a buffer overflow that can be triggered
by submitting a POST request with large amounts of data for certain
date / time fields. A remote attacker can reportedly exploit this
flaw to crash the web server or to execute arbitrary code on the
affected host.

See also :

http://www.ngssoftware.com/advisories/lotus-01.txt
http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21202431

Solution :

Upgrade to Lotus Domino Server version 6.0.5 / 6.5.4 Maintenance
Release or later.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)

Networks Security ID: 13130

Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2007 Tenable Network Security

Cables, Connectors

USB Memory uDrive Data Storage IN One Box WiFi Disk Sans File Server Micro SD
$14.79
USB Memory uDrive Data Storage IN One Box WiFi Disk Sans File Server Micro SD pictureNEW INTEL S1200SPSR DBS1200SPSR Intel Server Motherboard - Chipset 1 Pack Micro
$212.1
NEW INTEL S1200SPSR DBS1200SPSR Intel Server Motherboard - Chipset 1 Pack Micro pictureHP ProLiant G7 Dual-Core MicroServer 320 GB Hard Drive & 1.5 T HD
$145.0
HP ProLiant G7 Dual-Core MicroServer 320 GB Hard Drive & 1.5 T HD  picture708503-001 - HP PCA System Board (MB) N54L Microserver for ProLiant MICRO G7 ...
$319.99
708503-001 - HP PCA System Board (MB) N54L Microserver for ProLiant MICRO G7 ... picture


Discussions

No Discussions have been posted on this vulnerability.