CVE-2005-0986

NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:lotus_domino_server:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino_server:6.5.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:56

Type Values Removed Values Added
References () http://news.zdnet.co.uk/software/applications/0%2C39020384%2C39194293%2C00.htm - () http://news.zdnet.co.uk/software/applications/0%2C39020384%2C39194293%2C00.htm -
References () http://secunia.com/advisories/14858 - Vendor Advisory () http://secunia.com/advisories/14858 - Vendor Advisory
References () http://www-1.ibm.com/support/docview.wss?uid=swg21202446 - Vendor Advisory () http://www-1.ibm.com/support/docview.wss?uid=swg21202446 - Vendor Advisory
References () http://www.idefense.com/application/poi/display?id=224&type=vulnerabilities - Vendor Advisory () http://www.idefense.com/application/poi/display?id=224&type=vulnerabilities - Vendor Advisory
References () http://www.vupen.com/english/advisories/2005/0322 - () http://www.vupen.com/english/advisories/2005/0322 -

07 Nov 2023, 01:57

Type Values Removed Values Added
References
  • {'url': 'http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm', 'name': 'http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm', 'tags': [], 'refsource': 'MISC'}
  • () http://news.zdnet.co.uk/software/applications/0%2C39020384%2C39194293%2C00.htm -

Information

Published : 2005-05-02 04:00

Updated : 2024-11-20 23:56


NVD link : CVE-2005-0986

Mitre link : CVE-2005-0986

CVE.ORG link : CVE-2005-0986


JSON object : View

Products Affected

ibm

  • lotus_domino_server