CVE-2003-0122
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 10.11% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- ibm/lotus domino · ibm/lotus notes client
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=104757319829443&w=2Mailing List, Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101Broken Link
- http://www.cert.org/advisories/CA-2003-11.htmlThird Party Advisory, US Government Resource
- http://www.ciac.org/ciac/bulletins/n-065.shtmlBroken Link
- http://www.kb.cert.org/vuls/id/433489Third Party Advisory, US Government Resource
- http://www.rapid7.com/advisories/R7-0010.htmlNot Applicable
- http://www.securityfocus.com/bid/7037Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11526Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=104757319829443&w=2Mailing List, Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?rs=482&q=Domino&uid=swg21105101Broken Link
- http://www.cert.org/advisories/CA-2003-11.htmlThird Party Advisory, US Government Resource
- http://www.ciac.org/ciac/bulletins/n-065.shtmlBroken Link
- http://www.kb.cert.org/vuls/id/433489Third Party Advisory, US Government Resource
- http://www.rapid7.com/advisories/R7-0010.htmlNot Applicable
- http://www.securityfocus.com/bid/7037Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11526Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.