Description
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
Affected products
- ibm / lotus_domino4.6.1 – 4.6.1
- ibm / lotus_domino4.6.3 – 4.6.3
- ibm / lotus_domino4.6.4 – 4.6.4
- ibm / lotus_domino5.0 – 5.0
- ibm / lotus_domino5.0.1 – 5.0.1
- ibm / lotus_domino5.0.2 – 5.0.2
- ibm / lotus_domino5.0.3 – 5.0.3
- ibm / lotus_domino5.0.4 – 5.0.4
- ibm / lotus_domino5.0.4a – 5.0.4a
- ibm / lotus_domino5.0.5 – 5.0.5
- ibm / lotus_domino5.0.6 – 5.0.6
- ibm / lotus_domino5.0.6a – 5.0.6a
- ibm / lotus_domino5.0.7 – 5.0.7
- ibm / lotus_domino5.0.7a – 5.0.7a
- ibm / lotus_domino5.0.8 – 5.0.8
- ibm / lotus_domino5.0.8a – 5.0.8a
- ibm / lotus_domino5.0.9 – 5.0.9
- ibm / lotus_domino5.0.9a – 5.0.9a
- ibm / lotus_domino5.0.10 – 5.0.10
- ibm / lotus_domino5.0.11 – 5.0.11
- ibm / lotus_notes_client5.0 – 5.0
- ibm / lotus_notes_client5.0.1 – 5.0.1
- ibm / lotus_notes_client5.0.2 – 5.0.2
- ibm / lotus_notes_client5.0.3 – 5.0.3
- ibm / lotus_notes_client5.0.4 – 5.0.4
- ibm / lotus_notes_client5.0.5 – 5.0.5
- ibm / lotus_notes_client5.0.9a – 5.0.9a
- ibm / lotus_notes_client5.0.10 – 5.0.10
- ibm / lotus_notes_client5.0.11 – 5.0.11
- ibm / lotus_notes_clientr5 – r5
References
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2003-11.html
- MISChttp://www.ciac.org/ciac/bulletins/n-065.shtml
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104757545500368&w=2
- MISChttp://www.securityfocus.com/bid/7038
- VENDOR_ADVISORYhttp://www.rapid7.com/advisories/R7-0011.html
- MISChttp://www.kb.cert.org/vuls/id/411489
- MISChttp://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105060
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/11525