This script is Copyright (C) 2005-2011 Tenable Network Security, Inc.
Synopsis :
The remote web server is prone to denial of service attacks.
Description :
The remote host is running a version of Lotus Domino Server's web
service that is affected by a denial of service vulnerability.
By sending a specially crafted HTTP request with a long string of
unicode characters, a remote attacker can crash the nHTTP.exe process,
denying service to legitimate users.
Note that IBM has released technote #1202446 for this issue but has
been unable to reproduce it.
See also :
http://www.securityfocus.com/archive/1/395126
Solution :
Upgrade to Lotus Domino Server version 6.5.3 or later as it
is known to be unaffected.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 5.0
(CVSS2#E:H/RL:U/RC:ND)
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 17991 (domino_http_cgibin_unicode_dos.nasl)
Bugtraq ID: 13045
CVE ID: CVE-2005-0986