Mark Litchfield of NGSSoftware has discovered a high risk vulnerability in Lotus Domino Server. Versions affected include: Domino 6.0.5 Domino 6.5.4 The flaw permits execution of arbitrary code via a maliciously crafted POST request. Internal research has discovered to date, 6 attack vectors. This issue has been resolved in Lotus Domino as detailed at http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21202431 It can be downloaded from: http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21201845 NGSSoftware are going to withhold details of this flaw for three months. Full details will be published on the 12th of July 2005. This three month window will allow users of Lotus Domino the time needed to apply the patch before the details are released to the general public. This reflects NGSSoftware's approach to responsible disclosure. NGSSoftware Insight Security Research http://www.ngssoftware.com http://www.databasesecurity.com/ http://www.nextgenss.com/ +44(0)208 401 0070
This archive was generated by hypermail 2.1.3 : Tue Apr 12 2005 - 11:09:06 PDT