Description
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
Affected products
- ibm / lotus_domino4.6.1 – 4.6.1
- ibm / lotus_domino4.6.3 – 4.6.3
- ibm / lotus_domino4.6.4 – 4.6.4
- ibm / lotus_domino5.0 – 5.0
- ibm / lotus_domino5.0.1 – 5.0.1
- ibm / lotus_domino5.0.2 – 5.0.2
- ibm / lotus_domino5.0.3 – 5.0.3
- ibm / lotus_domino5.0.4 – 5.0.4
- ibm / lotus_domino5.0.4a – 5.0.4a
- ibm / lotus_domino5.0.5 – 5.0.5
- ibm / lotus_domino5.0.6 – 5.0.6
- ibm / lotus_domino5.0.6a – 5.0.6a
- ibm / lotus_domino5.0.7a – 5.0.7a
- ibm / lotus_domino5.0.8 – 5.0.8
- ibm / lotus_domino5.0.8a – 5.0.8a
- ibm / lotus_domino5.0.9 – 5.0.9
- ibm / lotus_domino5.0.9a – 5.0.9a
- ibm / lotus_domino5.0.10 – 5.0.10
- ibm / lotus_domino5.0.11 – 5.0.11
- ibm / lotus_notes_client5.0 – 5.0
- ibm / lotus_notes_client5.0.1 – 5.0.1
- ibm / lotus_notes_client5.0.2 – 5.0.2
- ibm / lotus_notes_client5.0.3 – 5.0.3
- ibm / lotus_notes_client5.0.4 – 5.0.4
- ibm / lotus_notes_client5.0.5 – 5.0.5
- ibm / lotus_notes_client5.0.9a – 5.0.9a
- ibm / lotus_notes_client5.0.10 – 5.0.10
- ibm / lotus_notes_client5.0.11 – 5.0.11
- ibm / lotus_notes_clientr5 – r5
References
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2003-11.html
- MISChttp://www.ciac.org/ciac/bulletins/n-065.shtml
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/11526
- MISChttp://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html
- VENDOR_ADVISORYhttp://www.rapid7.com/advisories/R7-0010.html
- MISChttp://www.kb.cert.org/vuls/id/433489
- MISChttp://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101
- MISChttp://www.securityfocus.com/bid/7037
- MAILING_LISThttp://marc.info/?l=bugtraq&m=104757319829443&w=2