Vulnerability Description
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Domino | 4.6.1 |
| Ibm | Lotus Notes Client | 5.0 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=104757319829443&w=2Mailing ListThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101Broken Link
- http://www.cert.org/advisories/CA-2003-11.htmlThird Party AdvisoryUS Government Resource
- http://www.ciac.org/ciac/bulletins/n-065.shtmlBroken Link
- http://www.kb.cert.org/vuls/id/433489Third Party AdvisoryUS Government Resource
- http://www.rapid7.com/advisories/R7-0010.htmlNot Applicable
- http://www.securityfocus.com/bid/7037PatchThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11526Third Party AdvisoryVDB Entry
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=104757319829443&w=2Mailing ListThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101Broken Link
- http://www.cert.org/advisories/CA-2003-11.htmlThird Party AdvisoryUS Government Resource
- http://www.ciac.org/ciac/bulletins/n-065.shtmlBroken Link
- http://www.kb.cert.org/vuls/id/433489Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2003-0122?
CVE-2003-0122 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authenticatio...
How severe is CVE-2003-0122?
CVE-2003-0122 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0122?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Domino, Ibm Lotus Notes Client.