Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against IBM Lotus Domino Web Server HTTP Header Buffer Overflow Vulnerability

Subscribe

Check Point Reference: CPAI-2008-084
Date Published:
Severity:
Last Updated:
Source: Secunia Advisory: SA30310
Industry Reference(s): CVE-2008-2240
Protection Provided by: VPN-1
  • NGX R65
  • NGX R62
  • NGX R61
  • NGX R60
VSX
  • NGX R65
InterSpect
  • NGX
Connectra
  • NGX R62
  • NGX R61
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
IBM Lotus Domino 6
IBM Lotus Domino 6.5
IBM Lotus Domino 7.0.x prior to 7.0.3 Fix Pack 1 (FP1)
IBM Lotus Domino 8.0.x prior to 8.0.1
Vulnerability Description
A stack buffer overflow vulnerability was reported in the IBM Lotus Domino Web Server application. IBM Lotus Domino is a server product that provides enterprise-grade e-mail, collaboration capabilities, and custom application platform. A remote attacker may exploit this vulnerability to execute arbitrary code on a vulnerable system.
Update/Patch Available
Upgrade to Domino 7.0.3 Fix Pack 1 (FP1) or 8.0.1.
Upgrade Central
Vulnerability Details
The vulnerability is due to an error in the IBM Lotus Domino Web Server application that fails to properly handle the header field in certain HTTP requests. An attacker can exploit this issue by sending a specially crafted HTTP request to the target server. Successful exploitation may allow the attacker to execute arbitrary code on the target system.

Protection Overview
By enabling this protection, SmartDefense will detect and block malformed HTTP requests sent to the vulnerable server. IPS-1 will detect and block HTTP requests with Accept-Language headers which exceed 32 bytes.

In order for the protection to be activated, update your VPN-1/InterSpect/Connectra product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

VPN-1 NGX R65 & R62

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Web Servers.
2. Select the following:

Block IBM Lotus Domino HTTP Header Buffer Overflow

3. In the configuration pane, under Settings > Mode, check Active.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Server Enforcement Violation
Attack Information: IBM Lotus Domino HTTP header buffer overflow vulnerability

VPN-1 NGX R61 & R60

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web Servers.
2. Select the following:

Block IBM Lotus Domino HTTP Header Buffer Overflow

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Server Enforcement Violation
Attack Information: IBM Lotus Domino HTTP header buffer overflow vulnerability

VPN-1 VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Web Servers.
2. Select the following:

Block IBM Lotus Domino HTTP Header Buffer Overflow

3. In the configuration pane, under Settings > Mode, check Active.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Server Enforcement Violation
Attack Information: IBM Lotus Domino HTTP header buffer overflow vulnerability

InterSpect NGX

How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the SmartDefense page of the profile.
2. In the SmartDefense tree, click Application Intelligence > Web Servers.
3. Select the following protection:

Block IBM Lotus Domino HTTP Header Buffer Overflow

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Server Enforcement Violation
Attack Information: IBM Lotus Domino HTTP header buffer overflow vulnerability

Connectra NGX R62 & R61

How Can I Protect My Network?
1. In the left-hand menu, click Security > SmartDefense > Application Intelligence.
2. In the Dynamic Attacks pane, select the following protection:

Block IBM Lotus Domino HTTP Header Buffer Overflow

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Attack Name: Web Server Enforcement Violation
Attack Information: IBM Lotus Domino HTTP header buffer overflow vulnerability

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Web Intelligence > WWW 2, and select the Strict Compliance protection group.
3. Click CVE-2008-2240 Lotus Domino HTTP Accept-Language header buffer overflow (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entry will be logged:

Alert Name: HTTP Compliance
Description: CVE-2008-2240 Lotus Domino HTTP Accept-Language header buffer overflow