Denial of Service Condition in Lotus Domino Web Server R5
An HTTP header-activated Denial of Service (DoS) condition exists in Lotus Domino Web Server R5 versions earlier than 5.0.7.
April 11, 2001
Reported April 11, 2001, byDefcom Labs.
VERSIONS AFFECTED
All releases of Lotus Domino Web Server R5 earlier than version 5.0.7 on all platforms
DESCRIPTION
AnHTTP header-activated Denial of Service (DoS) condition exists in Lotus DominoWeb Server R5 versions earlier than 5.0.7. An attacker can repeatedly requestdocument root (/) with various accept fields (accept: a, accept: aa, accept: aaaaso) that can result in the server's running out of physical memory. The servermight continue to run but won't accept any new requests, or the server processcan crash, requiring a server restart.
VENDOR RESPONSE
Thevendor, Lotus Development Corporation, has acknowledged this vulnerability andhas recommended that users upgrade to version 5.0.7. Users can obtain a copy ofthis upgrade from the Notes.netWeb site.
CREDIT
Discovered by PeterGründl.
About the Author
You May Also Like