CVE-2003-0122

Current Description

Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.

Basic Data

PublishedMarch 18, 2003
Last ModifiedDecember 12, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score5.0
SeverityMEDIUM
Exploitability Score10.0
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationIbmLotus Domino4.6.1*******
    2.3ApplicationIbmLotus Domino4.6.3*******
    2.3ApplicationIbmLotus Domino4.6.4*******
    2.3ApplicationIbmLotus Domino5.0*******
    2.3ApplicationIbmLotus Domino5.0.1*******
    2.3ApplicationIbmLotus Domino5.0.2*******
    2.3ApplicationIbmLotus Domino5.0.3*******
    2.3ApplicationIbmLotus Domino5.0.4*******
    2.3ApplicationIbmLotus Domino5.0.4a*******
    2.3ApplicationIbmLotus Domino5.0.5*******
    2.3ApplicationIbmLotus Domino5.0.6*******
    2.3ApplicationIbmLotus Domino5.0.6a*******
    2.3ApplicationIbmLotus Domino5.0.7a*******
    2.3ApplicationIbmLotus Domino5.0.8*******
    2.3ApplicationIbmLotus Domino5.0.8a*******
    2.3ApplicationIbmLotus Domino5.0.9*******
    2.3ApplicationIbmLotus Domino5.0.9a*******
    2.3ApplicationIbmLotus Domino5.0.10*******
    2.3ApplicationIbmLotus Domino5.0.11*******
    2.3ApplicationIbmLotus Notes Client5.0*******
    2.3ApplicationIbmLotus Notes Client5.0.1*******
    2.3ApplicationIbmLotus Notes Client5.0.2*******
    2.3ApplicationIbmLotus Notes Client5.0.3*******
    2.3ApplicationIbmLotus Notes Client5.0.4*******
    2.3ApplicationIbmLotus Notes Client5.0.5*******
    2.3ApplicationIbmLotus Notes Client5.0.9a*******
    2.3ApplicationIbmLotus Notes Client5.0.10*******
    2.3ApplicationIbmLotus Notes Client5.0.11*******
    2.3ApplicationIbmLotus Notes Clientr5*******

Vulnerable Software List

VendorProductVersions
Ibm Lotus Notes Client 5.0, 5.0.1, 5.0.10, 5.0.11, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.9a, r5
Ibm Lotus Domino 4.6.1, 4.6.3, 4.6.4, 5.0, 5.0.1, 5.0.10, 5.0.11, 5.0.2, 5.0.3, 5.0.4, 5.0.4a, 5.0.5, 5.0.6, 5.0.6a, 5.0.7a, 5.0.8, 5.0.8a, 5.0.9, 5.0.9a

References

NameSourceURLTags
20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authenticationhttp://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.htmlVULNWATCHThird Party Advisory
20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authenticationhttp://marc.info/?l=bugtraq&m=104757319829443&w=2BUGTRAQMailing List Third Party Advisory
CA-2003-11http://www.cert.org/advisories/CA-2003-11.htmlCERTThird Party Advisory US Government Resource
N-065http://www.ciac.org/ciac/bulletins/n-065.shtmlCIACBroken Link
VU#433489http://www.kb.cert.org/vuls/id/433489CERT-VNThird Party Advisory US Government Resource
http://www.rapid7.com/advisories/R7-0010.htmlhttp://www.rapid7.com/advisories/R7-0010.htmlMISCNot Applicable
7037http://www.securityfocus.com/bid/7037BIDPATCH Third Party Advisory VDB Entry Vendor Advisory
http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101CONFIRMBroken Link
lotus-nrpc-bo(11526)https://exchange.xforce.ibmcloud.com/vulnerabilities/11526XFThird Party Advisory VDB Entry