Das Notes Forum

Domino 9 und frühere Versionen => ND8: Administration & Userprobleme => Thema gestartet von: m3 am 10.04.09 - 08:49:43

Titel: IBM Lotus Domino RFC822 Blobs Remote Denial of Service Vulnerability
Beitrag von: m3 am 10.04.09 - 08:49:43
http://www.vupen.com/english/advisories/2009/0986

A vulnerability has been identified in IBM Lotus Domino, which could be exploited by remote attackers to cause a denial of service. This issue is caused by an error when processing RFC822 attachments with malformed root entities, which could be exploited to crash an affected server via a message containing a specially crafted attachment.

Affected Products
IBM Lotus Domino versions prior to 8.5 Interim Fix 3 (85IF3)
IBM Lotus Domino versions prior to 8.0.2FP1 Interim Fix 1 (802FP1IF1)

Solution
Upgrade to IBM Lotus Domino version 8.5 Interim Fix 3 (85IF3) or 8.0.2FP1 Interim Fix 1 (802FP1IF1) :
http://www-933.ibm.com/support/fixcentral/