Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gain a shell remotely >> Lotus Domino Server Date Fields Overflow Vulnerability


Vulnerability Assessment Details

Lotus Domino Server Date Fields Overflow Vulnerability

Vulnerability Assessment Summary
Checks for date fields overflow vulnerability in Lotus Domino Server

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server is susceptible to a buffer overflow
vulnerability.

Description :

According to its banner, the remote host is running a version of Lotus
Domino Server that is prone to a buffer overflow that can be triggered
by submitting a POST request with large amounts of data for certain
date / time fields. A remote attacker can reportedly exploit this
flaw to crash the web server or to execute arbitrary code on the
affected host.

See also :

http://www.ngssoftware.com/advisories/lotus-01.txt
http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21202431

Solution :

Upgrade to Lotus Domino Server version 6.0.5 / 6.5.4 Maintenance
Release or later.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)

Networks Security ID: 13130

Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2007 Tenable Network Security

Cables, Connectors

PENGO (1983) BRAND NEW FACTORY SEALED LARGE BOX (16k Cart) ATARI 400/800
$50.0
PENGO (1983) BRAND NEW  FACTORY SEALED LARGE BOX  (16k Cart)  ATARI 400/800   pictureAtari 800/65XE/130XE Color S-Video & 2 Channel Audio Cable Tested
$14.74
Atari 800/65XE/130XE Color S-Video & 2 Channel Audio Cable Tested pictureNvidia Shield K1 Retro Gaming Ed. Kodi Nintendo Atari Sega *ROOTED* 64GB SD Card
$89.42
Nvidia Shield K1 Retro Gaming Ed. Kodi Nintendo Atari Sega *ROOTED* 64GB SD Card pictureThe Second Book of Machine Language Richard Mansfield Vtg Atari Apple Commodore
$26.95
The Second Book of Machine Language Richard Mansfield Vtg Atari Apple Commodore picture


Discussions

No Discussions have been posted on this vulnerability.