Overview
A buffer overflow vulnerability may be exploited via the Lotus Domino Web Retriever. Versions prior to 5.0.12 and 6.0 are affected.
Description
According to the Rapid7 Advisory: The Lotus Notes/Domino Web Retriever task is responsible for retrieving web pages on behalf of Notes users who want to access the web via their Notes server. |
Impact
This vulnerability may be used to cause a denial of service. |
Solution
Lotus has published a support document for this issue. Upgrade to version 5.0.12 or 6.0 Gold or 6.0.1. |
In their support document, Lotus recommends disabling the WEB task on the server as a workaround. This task is not enabled by default. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Rapid7, Inc. Security Advisories and Lotus for reporting this vulnerability.
This document was written by Jason A Rafail based on information provided by Rapid7, Inc. and Lotus.
Other Information
CVE IDs: | None |
Severity Metric: | 12.66 |
Date Public: | 2003-03-06 |
Date First Published: | 2003-03-13 |
Date Last Updated: | 2003-03-18 15:54 UTC |
Document Revision: | 17 |