HZGN.COM
welcome to my space
X
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Welcome to:hzgn.com
Search:  
NAVIGATION: Home >>
CERT Confirms Lotus, Domino Flaws
Published by: jane 2008-11-20

The CERT Coordination Center on Wednesday issued an alert confirming several buffer overflow vulnerabilities in Lotus Notes and Domino that could lead to denial-of-service scenarios.

CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many ::
Lotus Software evaluated the Lotus Domino Server for vulnerabilities using used to check routers and switches for several known SNMP security flaws.
http://www.cert.org/advisories/CA-2002-03.html
HOME
The CERT/CC advisory was issued primary to clear up confusion surrounding several security holes detected last month by research firms NGSS and Rapid7.

Systems affected by the bugs include Lotus Notes and Domino versions prior to 5.0.12 and 6.0 Gold. Download locations for vendor patches can be found within the CERT advisory.

The Center confirmed buffer overflow vulnerabilities in Lotus iNotes and Lotus Domino Web Server which leaves unpatched systems open to DoS attacks. One of those Lotus iNotes flaws, described as "critical" by NGSS, can be exploited by an attacker to run code in the security context of the account running the Domino Web Services.

The Center also issued a clarification for another vulnerability originally reported in an iNotes ActiveX control. "The vulnerable code is not specific to iNotes or ActiveX," CERT/CC said, noting that the iNotes ActiveX control was an attack vector for the vulnerability and is not the affected code base.

"Because this issue is not specific to ActiveX, Lotus Notes clients and Domino Servers running on platforms other than Microsoft Windows may be affected," it warned.

Security research firm Rapid7 also found several holes in Lotus Domino prior to version 5.0.12. It said the Lotus Domino Server was susceptible to a pre-authentication buffer overflow during Notes authentication. The Lotus Domino Web Retriever also contained a buffer overflow vulnerability.

Rapid7 also warned of holes in Lotus Domino pre-release and beta versions of 6.0 were also affected by multiple vulnerabilities in LDAP handling code. "The impact of these vulnerabilities range from denial of service to data corruption and the potential to execute arbitrary code," the Center warned.

From shapj@us.ibm.com Mon Nov 1 20:26:57 1999 Date: Mon, 1 Nov ::
File Format: UnrecognizedWhile the specific encodings are different, the Lotus Domino server uses an essentially .. operation to confirm that two purses come from the same mint.
http://www.eros-os.org/pipermail/e-lang/1999-November.txt.gz
HOME

It noted that patches are available only for some of the vulnerabilities. Until patches are made available for all, IT administrators are encouraged to block access from outside the network perimeter or configure Lotus Notes to help mitigate successful exploitation of the flaws.




Lindows.com Launches New Developer Program
OpenOffice.org Debuts 1.1 Beta

You are looking at:hzgn.com's CERT Confirms Lotus, Domino Flaws, click hzgn.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about CERT Confirms Lotus, Domino Flaws , Please add it free.
  • another nail gun question
  • rigid band saw
  • ts 2400
  • ts2424 good bad otherwise
  • brad vs finish nail
  • ts2400 10 portable saw is it worth it
  • brad or finish nailer
  • squaring wood for gluing
  • compressor psi
  • measuring angles to be cut
  • jp 610 fence redesign
  • rebates
  • incra ts fence
  • flat face on wider boards
  • tenon jig for my ts 2400
  • smoking wood
  • make your work measure up
  • dado blades on the ts2400
  • non flammable solvent
  • eb4424 sander problem
  • oscillating spindle sander
  • looking for plans
  • router bits
  • scratches in a table saw top
  • scroll saw
  • new ridgid drill press
  • ridgid ts2400 my first table saw
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzgn.com        Site made:CFZ