NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://news.zdnet.co.uk/software/applications/0%2C39020384%2C39194293%2C00.htm - | |
References | () http://secunia.com/advisories/14858 - Vendor Advisory | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg21202446 - Vendor Advisory | |
References | () http://www.idefense.com/application/poi/display?id=224&type=vulnerabilities - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2005/0322 - |
07 Nov 2023, 01:57
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:56
NVD link : CVE-2005-0986
Mitre link : CVE-2005-0986
CVE.ORG link : CVE-2005-0986
JSON object : View
Products Affected
ibm
- lotus_domino_server
CWE