Description
Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.
Affected products
- ibm / lotus_domino_server4.6.1 – 4.6.1
- ibm / lotus_domino_server4.6.3 – 4.6.3
- ibm / lotus_domino_server4.6.4 – 4.6.4
- ibm / lotus_domino_server5.0 – 5.0
- ibm / lotus_domino_server5.0.1 – 5.0.1
- ibm / lotus_domino_server5.0.2 – 5.0.2
- ibm / lotus_domino_server5.0.3 – 5.0.3
- ibm / lotus_domino_server5.0.4 – 5.0.4
- ibm / lotus_domino_server5.0.5 – 5.0.5
- ibm / lotus_domino_server5.0.6 – 5.0.6
- ibm / lotus_domino_server5.0.7 – 5.0.7
- ibm / lotus_domino_server5.0.7a – 5.0.7a
- ibm / lotus_domino_server5.0.8 – 5.0.8
- ibm / lotus_domino_server5.0.9 – 5.0.9
References
- MISChttp://archives.neohapsis.com/archives/vulnwatch/2002-q1/0037.html
- MISChttp://www.securityfocus.com/bid/4020
- MISChttp://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/945e97608fda942a85256b37007905b1?OpenDocument&Highlight=0%2CJCHN547JWV
- MISChttp://www.securityfocus.com/bid/4019
- MISChttp://www.securityfocus.com/archive/1/253830
- MISChttp://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/a77f8a5132cce70085256b8000792112?OpenDocument&Highlight=0%2CJCHN4UMKLA