IBM.Lotus.Domino.LDAP.Bind.Request.Integer.Overflow
Description
This indicates an attack attempt against an integer overflow in IBM Lotus Domino's LDAP service.
The vulnerability is due to incorrect handling of the name parameter by the library nnotes.dll when it processes ASN.1 encoded LDAP BindRequests. A remote unauthenticated attacker can exploit this vulnerability to cause a heap buffer overflow.
Affected Products
IBM Lotus Domino Enterprise Server 6.5.5
IBM Lotus Domino Enterprise Server 6.5.4
IBM Lotus Domino Enterprise Server 6.5.2
IBM Lotus Domino Enterprise Server 6.0.5
IBM Lotus Domino Enterprise Server 6.0.1
IBM Lotus Domino Enterprise Server 5.0.13
IBM Lotus Domino Enterprise Server 5.0.12
IBM Lotus Domino Enterprise Server 5.0.9
IBM Lotus Domino Enterprise Server 5.0.3
IBM Lotus Domino 8.5.2
IBM Lotus Domino 8.5.1 Fix Pack 2
IBM Lotus Domino 8.5.1
IBM Lotus Domino 8.5
IBM Lotus Domino 8.0.2 Fix Pack 5
IBM Lotus Domino 8.0.2
IBM Lotus Domino 8.0.1
IBM Lotus Domino 7.0.4
IBM Lotus Domino 7.0.3 Fix Pack 1 (FP1)
IBM Lotus Domino 7.0.3
IBM Lotus Domino 7.0.2 FP3
IBM Lotus Domino 7.0.2 FP2
IBM Lotus Domino 7.0.2 FP1
IBM Lotus Domino 7.0.2
IBM Lotus Domino 7.0.1
IBM Lotus Domino 7.0
IBM Lotus Domino 6.5.6
IBM Lotus Domino 6.5.5 FP3
IBM Lotus Domino 6.5.5 FP2
IBM Lotus Domino 6.5.5 FP1
IBM Lotus Domino 6.5.5
IBM Lotus Domino 6.5.4 FP 2
IBM Lotus Domino 6.5.4 FP 1
IBM Lotus Domino 6.5.4
IBM Lotus Domino 6.5.3
IBM Lotus Domino 6.5.2 FP 1
IBM Lotus Domino 6.5.2
IBM Lotus Domino 6.5.1
IBM Lotus Domino 6.5 .0
IBM Lotus Domino 6.0.5
IBM Lotus Domino 6.0.4
IBM Lotus Domino 6.0.3
IBM Lotus Domino 6.0.2 CF2
IBM Lotus Domino 6.0.2
IBM Lotus Domino 6.0.1
IBM Lotus Domino 6.0
IBM Lotus Domino 5.0.13
IBM Lotus Domino 8.5.1.1
IBM Lotus Domino 8.5.0.1
IBM Lotus Domino 8.5 FP1
IBM Lotus Domino 8.5
IBM Lotus Domino 8.0.2.4
IBM Lotus Domino 8.0.2.3
IBM Lotus Domino 8.0.2.2
IBM Lotus Domino 8.0.2.1
IBM Lotus Domino 8.0
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Refer to the vendor's website for a suggested work around.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |