First published: Thu May 22 2008(Updated: )
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino R5 | =6.0 | |
IBM Lotus Domino R5 | =6.5 | |
IBM Lotus Domino R5 | =7.0 | |
IBM Lotus Domino R5 | =8.0 | |
IBM Lotus Domino R5 | =8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2240 is classified as a high severity vulnerability due to its potential to allow remote code execution and cause denial of service.
To mitigate CVE-2008-2240, update IBM Lotus Domino to version 7.0.3 FP1 or 8.0.1 or later.
CVE-2008-2240 affects IBM Lotus Domino versions 6.0, 6.5, 7.0, and 8.0 prior to 8.0.1.
CVE-2008-2240 is a stack-based buffer overflow vulnerability.
Yes, CVE-2008-2240 can cause a denial of service by crashing the daemon.