[NEWS] Lotus Domino Buffer Overflow (Time/Date Field)

From: SecuriTeam (support_at_securiteam.com)
Date: 06/23/05

  • Next message: SecuriTeam: "[EXPL] FRB Remote Command Execution (Exploit)"
    To: list@securiteam.com
    Date: 23 Jun 2005 12:38:04 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Lotus Domino Buffer Overflow (Time/Date Field)
    ------------------------------------------------------------------------

    SUMMARY

    " <http://www.lotus.com/products/product4.nsf/wdocs/dominohomepage> IBM
    Lotus Domino server software combines enterprise-class messaging and
    calendar/ scheduling capabilities with a robust platform for collaborative
    applications on a wide variety of operating systems."

    A buffer overflow vulnerability in Lotus Domino allows remote attackers to
    execute arbitrary code on the server.

    DETAILS

    Vulnerable Systems:
     * Lotus Domino version 6.5.4
     * Lotus Domino version 6.0.5

    A buffer overflow vulnerability occurs whenever a user submits large
    amount of data to certain time/date fields that can be updated from the
    web interface. This vulnerability can be exploited by a malicious user
    with access to the web server to cause the Lotus Domino server to execute
    arbitrary code and to crash, resulting in a Denial of Server

    Vendor Status:
    The vendor has issued a patch for both versions:
    <http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21201845>
    http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21201845

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:mark@ngssoftware.com> NGS
    Software.
    The vendor advisory can be found at:
    <http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21202431>
    http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21202431

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[EXPL] FRB Remote Command Execution (Exploit)"

    Relevant Pages

    • [NEWS] Default Configuration Information Disclosure in Lotus Domino (Including Password Hashes)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... * Lotus Domino R5 WebMail ... hidden field called "HTTPPassword" which contains the password hash. ... Vendor response stating that they couldn't find a way to ...
      (Securiteam)
    • [NEWS] IBM Lotus Domino IMAP Buffer Overflow Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... IBM Lotus Domino IMAP Buffer Overflow Vulnerability ... Remote exploitation of a buffer overflow vulnerability within IBM Corp.'s ... This allows an attacker to take complete control of the compromised ...
      (Securiteam)
    • [EXPL] IBM Lotus Domino Server Web Service DoS (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... a vulnerability in Lotus Domino Server web service ...
      (Securiteam)
    • [NEWS] IBM Lotus Domino Server Web Service DoS Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Lotus Domino Server web service allows attackers to crash the service, ... This results in the immediate crash of nHTTP.EXE and is not reported to ... Exploitation of this vulnerability allows unauthenticated remote attackers ...
      (Securiteam)
    • [NEWS] IBM DB2 Buffer Overflow Vulnerabilities (rec2xml, generate_distfile)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... procedure suffers from a stack based buffer overflow vulnerability. ...
      (Securiteam)