Denial of Service Condition in Lotus Domino Web Server R5

An HTTP header-activated Denial of Service (DoS) condition exists in Lotus Domino Web Server R5 versions earlier than 5.0.7.

Ken Pfeil

April 11, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 11, 2001, byDefcom Labs.

 

VERSIONS AFFECTED

 

  • All releases of Lotus Domino Web Server R5 earlier than version 5.0.7 on all platforms

DESCRIPTION

AnHTTP header-activated Denial of Service (DoS) condition exists in Lotus DominoWeb Server R5 versions earlier than 5.0.7. An attacker can repeatedly requestdocument root (/) with various accept fields (accept: a, accept: aa, accept: aaaaso) that can result in the server's running out of physical memory. The servermight continue to run but won't accept any new requests, or the server processcan crash, requiring a server restart.

 

VENDOR RESPONSE

 

Thevendor, Lotus Development Corporation, has acknowledged this vulnerability andhas recommended that users upgrade to version 5.0.7. Users can obtain a copy ofthis upgrade from the Notes.netWeb site.

 

CREDIT

Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like