fighting for truth, justice, and a kick-butt lotus notes experience.

Security Advisory: Lotus Domino Denial of Service Vulnerability during Notes authentication processing

 21 Dezember 2011 21:46:12
Zeit jetzt aller spätestens ein Update einzuspielen :-(

Security Advisory CVE ID:
Fortiguard contacted IBM to report a denial of service attack when a malicious packet is supplied to the Domino Server via Notes RPC. For more information, see Fortiguard Advisory FG-VD-11-007 at

If an attacker can monitor and record all communications between a Notes client and a Domino server then it is possible to crash the Domino server by modifying a specific packet, in a specific way, during a specific operation. 

Note: the use case cited by Fortiguard is very rare and, as such, requires careful coordination by the attacker.

Resolving the problem
Affected versions

The following releases of IBM Lotus Domino Server are susceptible to this malicious attack:
              8.5.2 FP3 and earlier
Recommended Fix

FG-VD-11-007 has been investigated by IBM and is tracked in SPR# KLYH8FTK5Y. To address the issues, you are encouraged to apply the following IBM Lotus Domino Server releases:
              8.5.2 Fix Pack 4 (or later Fix Packs)