CVE-2002-1624: Buffer Overflow
Published Dec 31, 2002
·Updated
Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
Affected Software
14 affected components
IBM Lotus Domino=5.0.2
IBM Lotus Domino=5.0.1
IBM Lotus Domino=5.0.3
IBM Lotus Domino=5.0.9
IBM Lotus Domino=5.0.4
IBM Lotus Domino=5.0.4a
IBM Lotus Domino=5.0.6
IBM Lotus Domino=5.0.6a
IBM Lotus Domino=5.0
IBM Lotus Domino=5.0.7
IBM Lotus Domino=5.0.9a
IBM Lotus Domino=5.0.5
IBM Lotus Domino=5.0.8
IBM Lotus Domino=5.0.7a
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Mar 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1624?
The severity of CVE-2002-1624 is high due to the potential for denial of service and remote code execution.
2
How do I fix CVE-2002-1624?
To fix CVE-2002-1624, upgrade to Lotus Domino version R5.0.10 or later.
3
What versions of IBM Lotus Domino are affected by CVE-2002-1624?
CVE-2002-1624 affects IBM Lotus Domino versions 5.0.1 through 5.0.9, among others.
4
What type of attack does CVE-2002-1624 enable?
CVE-2002-1624 enables remote attackers to exploit a buffer overflow and potentially execute arbitrary code.
5
Can CVE-2002-1624 cause a denial of service?
Yes, CVE-2002-1624 can cause a denial of service by crashing the Lotus Domino web server.