Intrusion Prevention

IBM.Lotus.Domino.LDAP.Bind.Request.Integer.Overflow

Description

This indicates an attack attempt against an integer overflow in IBM Lotus Domino's LDAP service.
The vulnerability is due to incorrect handling of the name parameter by the library nnotes.dll when it processes ASN.1 encoded LDAP BindRequests. A remote unauthenticated attacker can exploit this vulnerability to cause a heap buffer overflow.

Affected Products

IBM Lotus Domino Enterprise Server 6.5.5
IBM Lotus Domino Enterprise Server 6.5.4
IBM Lotus Domino Enterprise Server 6.5.2
IBM Lotus Domino Enterprise Server 6.0.5
IBM Lotus Domino Enterprise Server 6.0.1
IBM Lotus Domino Enterprise Server 5.0.13
IBM Lotus Domino Enterprise Server 5.0.12
IBM Lotus Domino Enterprise Server 5.0.9
IBM Lotus Domino Enterprise Server 5.0.3
IBM Lotus Domino 8.5.2
IBM Lotus Domino 8.5.1 Fix Pack 2
IBM Lotus Domino 8.5.1
IBM Lotus Domino 8.5
IBM Lotus Domino 8.0.2 Fix Pack 5
IBM Lotus Domino 8.0.2
IBM Lotus Domino 8.0.1
IBM Lotus Domino 7.0.4
IBM Lotus Domino 7.0.3 Fix Pack 1 (FP1)
IBM Lotus Domino 7.0.3
IBM Lotus Domino 7.0.2 FP3
IBM Lotus Domino 7.0.2 FP2
IBM Lotus Domino 7.0.2 FP1
IBM Lotus Domino 7.0.2
IBM Lotus Domino 7.0.1
IBM Lotus Domino 7.0
IBM Lotus Domino 6.5.6
IBM Lotus Domino 6.5.5 FP3
IBM Lotus Domino 6.5.5 FP2
IBM Lotus Domino 6.5.5 FP1
IBM Lotus Domino 6.5.5
IBM Lotus Domino 6.5.4 FP 2
IBM Lotus Domino 6.5.4 FP 1
IBM Lotus Domino 6.5.4
IBM Lotus Domino 6.5.3
IBM Lotus Domino 6.5.2 FP 1
IBM Lotus Domino 6.5.2
IBM Lotus Domino 6.5.1
IBM Lotus Domino 6.5 .0
IBM Lotus Domino 6.0.5
IBM Lotus Domino 6.0.4
IBM Lotus Domino 6.0.3
IBM Lotus Domino 6.0.2 CF2
IBM Lotus Domino 6.0.2
IBM Lotus Domino 6.0.1
IBM Lotus Domino 6.0
IBM Lotus Domino 5.0.13
IBM Lotus Domino 8.5.1.1
IBM Lotus Domino 8.5.0.1
IBM Lotus Domino 8.5 FP1
IBM Lotus Domino 8.5
IBM Lotus Domino 8.0.2.4
IBM Lotus Domino 8.0.2.3
IBM Lotus Domino 8.0.2.2
IBM Lotus Domino 8.0.2.1
IBM Lotus Domino 8.0

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Refer to the vendor's website for a suggested work around.
https://www-304.ibm.com/support/docview.wss?uid=swg21461514

CVE References

CVE-2011-0917

Other References

SA43224 ZDI-11-047