CVE-2000-0023: Buffer Overflow
Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the Domino HTTP server (or its HTTP configuration) to reject or enforce a conservative maximum URL/request-line length so that excessively long URLs are not accepted.
IBM Lotus Domino HTTP server maximum URL length = reject or limit excessively long URLs - Compensating control
Deploy a web application firewall (WAF) or reverse proxy in front of the Domino HTTP server to inspect and block requests with excessively long or malformed URLs/request lines.
- Compensating control
Restrict network exposure of the Domino HTTP service using perimeter firewalls or ACLs (limit allowed source IP ranges) to reduce risk from remote attackers.
- Operational
Monitor Domino HTTP logs and availability for signs of crashes or abnormal HTTP requests; implement the above mitigations immediately and apply any IBM-issued security update or patch as soon as it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0023?
CVE-2000-0023 has a high severity rating due to its potential to cause a denial of service.
How do I fix CVE-2000-0023?
To fix CVE-2000-0023, update your Lotus Domino Server to a patched version that addresses this buffer overflow vulnerability.
What systems are affected by CVE-2000-0023?
CVE-2000-0023 affects Lotus Domino Server versions 4.6.x and 4.6.
What type of attack does CVE-2000-0023 facilitate?
CVE-2000-0023 facilitates a remote denial of service attack through a crafted long URL.
Is CVE-2000-0023 a critical vulnerability?
Yes, CVE-2000-0023 is considered critical, as it can render the server inoperable.