First published: Tue Aug 21 2012(Updated: )
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =8.5.0 | |
IBM Lotus Domino | =8.5.0.1 | |
IBM Lotus Domino | =8.5.1.1 | |
IBM Lotus Domino | =8.5.1.2 | |
IBM Lotus Domino | =8.5.1.3 | |
IBM Lotus Domino | =8.5.1.4 | |
IBM Lotus Domino | =8.5.1.5 | |
IBM Lotus Domino | =8.5.2.0 | |
IBM Lotus Domino | =8.5.2.1 | |
IBM Lotus Domino | =8.5.2.2 | |
IBM Lotus Domino | =8.5.2.3 | |
IBM Lotus Domino | =8.5.2.4 | |
IBM Lotus Domino | =8.5.3.0 | |
IBM Lotus Domino | =8.5.3.1 | |
IBM Lotus Domino | =8.5.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3301 is classified as a moderate severity vulnerability due to its potential for HTTP response splitting attacks.
To fix CVE-2012-3301, upgrade IBM Lotus Domino to version 8.5.4 or later where the vulnerability is resolved.
The potential impacts of CVE-2012-3301 include the ability for attackers to inject arbitrary HTTP headers which can lead to various attacks, such as phishing and cache poisoning.
CVE-2012-3301 affects multiple versions of IBM Lotus Domino including all versions prior to 8.5.4.
Yes, CVE-2012-3301 particularly affects Mozilla Firefox 3.0.9 and earlier versions, alongside unspecified browsers.