First published: Wed Apr 06 2005(Updated: )
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino Server | =6.0.3 | |
IBM Lotus Domino Server | =6.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0986 has a severity rating that indicates it allows for a denial of service attack against the affected IBM Lotus Domino Server versions.
To fix CVE-2005-0986, upgrade your IBM Lotus Domino Server to a version that is not affected by this vulnerability.
CVE-2005-0986 affects IBM Lotus Domino Server versions 6.0.3 and 6.5.1, among potentially others.
CVE-2005-0986 exploits a deep recursion vulnerability that can lead to a crash of the nHTTP.exe process.
Yes, CVE-2005-0986 is a remote vulnerability that allows attackers to crash the server through crafted GET requests.