First published: Mon Dec 11 2000(Updated: )
Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the "MAIL FROM" command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino Enterprise Server | =5.0.1 | |
IBM Lotus Domino Enterprise Server | =5.0.2 | |
IBM Lotus Domino Enterprise Server | =5.0.2b | |
IBM Lotus Domino Enterprise Server | =5.0.3 | |
IBM Lotus Domino Enterprise Server | =5.0.4 | |
IBM Lotus Domino Mail Server | =5.0.1 | |
IBM Lotus Domino Mail Server | =5.0.2 | |
IBM Lotus Domino Mail Server | =5.0.2b | |
IBM Lotus Domino Mail Server | =5.0.3 | |
IBM Lotus Domino Mail Server | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1047 has a medium severity rating due to its potential to cause denial of service and execute arbitrary commands.
To fix CVE-2000-1047, upgrade to Lotus Domino version 5.0.5 or later, which addresses this vulnerability.
CVE-2000-1047 affects IBM Lotus Domino Enterprise Server and Mail Server versions 5.0.1 through 5.0.4.
Yes, CVE-2000-1047 can lead to crashes or denial of service due to the buffer overflow in the SMTP service.
Yes, CVE-2000-1047 can be exploited remotely by attackers through crafted SMTP commands.