CVE-2004-0029: Medium severity IBM Lotus Domino vulnerability
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the world-writable permission on the notes.ini file so local users cannot modify it. For example, on Linux run: chmod o-w /path/to/notes.ini (ensure the file is owned appropriately and not world-writable).
Lotus Notes Domino (notes.ini) file permissions = remove world-writable (not world-writable)
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0029?
CVE-2004-0029 is considered a high severity vulnerability due to its potential to allow local users to gain unauthorized privileges in Lotus Notes Domino.
How do I fix CVE-2004-0029?
To fix CVE-2004-0029, change the permissions of the notes.ini file to restrict write access only to authorized users.
What systems are affected by CVE-2004-0029?
CVE-2004-0029 specifically affects IBM Lotus Domino version 6.0.2 running on Linux.
What is the impact of CVE-2004-0029?
The impact of CVE-2004-0029 allows local users to modify the Notes configuration, potentially leading to privilege escalation and system compromise.
Is CVE-2004-0029 still relevant today?
While CVE-2004-0029 is an older vulnerability, it remains relevant for organizations still using unsupported versions of Lotus Domino.