Overview
A remotely exploitable buffer overflow exists in versions of IBM's Lotus Domino web server prior to R5.0.10.
Description
| A remotely exploitable buffer overflow exists in the Lotus Domino web server. The overflow can occur as the result of an overly long HTTP Authenticate header containing certain non-ASCII characters. For more information, please see the IBM Technote. | 
Impact
| An intruder can execute arbitrary code with the privileges of the Lotus Domino web server. | 
Solution
| Upgrade to R5.0.10 or later. | 
| Workaround Log to text files instead of domlog.nsf. | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was discovered by The Relay Group.
This document was written by Ian A. Finlay.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 36.00 | 
| Date Public: | 2002-04-23 | 
| Date First Published: | 2003-01-13 | 
| Date Last Updated: | 2003-01-13 15:28 UTC | 
| Document Revision: | 6 |