CVE-2002-0086: Buffer Overflow
Published Mar 7, 2002
·Updated
Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) NotesExecDirectory or (2) PATH environment variable.
Affected Software
2 affected components
IBM Lotus Domino=5.0.7
IBM Lotus Domino=5.0.4
Remediation
Patch Available
Patch Available
Event History
Mar 7, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0086?
CVE-2002-0086 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
2
How do I fix CVE-2002-0086?
The resolution for CVE-2002-0086 is to upgrade Lotus Domino to a patched version that addresses the buffer overflow issue.
3
Which versions of Lotus Domino are affected by CVE-2002-0086?
CVE-2002-0086 affects Lotus Domino versions 5.0.4 and 5.0.7 on Linux.
4
What is the exploit mechanism of CVE-2002-0086?
CVE-2002-0086 exploits a buffer overflow in the bindsock function, allowing exploitation via long environment variables.
5
Can CVE-2002-0086 be exploited remotely?
CVE-2002-0086 requires local access, meaning it cannot be exploited remotely.