Security Advisory: Lotus Domino Denial of Service Vulnerability during Notes authentication processing


From TN 1575247

Fortiguard contacted IBM to report a denial of service attack when a malicious packet is supplied to the Domino Server via Notes RPC.  This vulnerability is resolved in releases starting with 8.5.2 FP4 and 8.5.3

The following releases of IBM Lotus Domino Server are susceptible to this malicious attack:

  • 8.5.2 FP3 and earlier
  • 8.5.1
  • 8.5
  • 8.0.x

FG-VD-11-007  has been investigated by IBM and is tracked in SPR# KLYH8FTK5Y.  To address the issues, you are encouraged to apply the following IBM Lotus Domino Server releases:

  • 8.5.3
  • 8.5.2 Fix Pack 4 (or later Fix Packs)