CVE-2006-0121: High severity IBM Lotus Domino vulnerability
Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0121?
CVE-2006-0121 is considered a moderate severity vulnerability due to potential denial of service attacks.
How do I fix CVE-2006-0121?
To fix CVE-2006-0121, upgrade to IBM Lotus Notes or Domino Server version 6.5.5 or later.
Which versions are affected by CVE-2006-0121?
CVE-2006-0121 affects versions 6.5.0 through 6.5.4 of IBM Lotus Notes and Domino Server.
What kind of attack does CVE-2006-0121 facilitate?
CVE-2006-0121 allows attackers to exploit memory leaks, leading to a denial of service through crashes due to excessive memory consumption.
Is there a workaround for CVE-2006-0121?
There is no documented workaround for CVE-2006-0121; upgrading to a fixed version is the recommended solution.