Lotus Domino SMTP ENVID Variable Handling RCE

critical Nessus Plugin ID 10543

Synopsis

The remote SMTP server is affected by a remote code execution vulnerability.

Description

The Lotus Domino SMTP server running on the remote host is affected by a buffer overflow condition due to improper validation of input to the ENVID variable within a MAIL FROM command. An unauthenticated, remote attack can exploit this, via a overly long ENVID value, to cause a denial of service condition or possibly the execution of arbitrary code.

Solution

Upgrade to Lotus Notes/Domino version 5.0.6 or later. This reportedly fixes the vulnerability.

See Also

http://www.nessus.org/u?67370f13

Plugin Details

Severity: Critical

ID: 10543

File Name: lotus_envid.nasl

Version: 1.34

Type: remote

Published: 11/6/2000

Updated: 11/15/2018

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:lotus:domino_enterprise_server

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/3/2000

Reference Information

CVE: CVE-2000-1047

BID: 1905