All the latest UK technology news, reviews and analysis

Lotus moves to fix Domino flaw

by Ian Lynch

11 Jan 2001

Be the first to comment

  • Tweet this

Lotus has given the highest priority to fixing a flaw with its Domino webserver, and has said it hopes to have a fix ready by 13 January.

The problem leaves the webserver vulnerable to attack by Netscape 4.x users who can gain access to files located on the system drive if the user knows the path and file name.

The problem was one of two reported to the moderated security mailing list bugtraq late on Monday, prompting some consultants, such as MIS Corporate Defence Solutions (MIS), to inform clients that they may have no secure alternative but to close down their servers until a workaround was published.

A spokeswoman for Lotus said it was aware of the webserver issue and hoped to have a patch ready by 13 January. She added that a full statement, including a workaround for the problem, has been posted on the Notes/Domino Gold release Forum at the notes.net website.

The other problem referred to a claim that any authorised user of the Domino mail system could gain unauthorised access to any mailbox in the system by modifying the traffic between their client and Domino server or by modifying the client software itself.

However, other security professionals have since informed bugtraq that they have been unable to reproduce the email issue and it seems that this claim has little merit.

Experts said they weren't surprised that the webserver problem had been discovered and predicted that more would come to light as security professionals switched their focus from Microsoft products to those of other vendors.

Paul Rogers, a network security analyst at MIS, said: "It was only a matter of time before a serious vulnerability was discovered in Lotus Domino, or similar products, as security professionals start to put them under the same degree of scrutiny they do products from Microsoft."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

IT Security Specialist Move in2 Solutions /Pre-Sales in 18 mths

IT Security Specialist Move in2 Solutions /Pre-Sales...

SOFTWARE ENGINEER - UNIX C JAVA ORACLE

SOFTWARE ENGINEER - BERKS - to £34k plus package WAREHOUSE...

Senior Project Manager

We currently have a position for a Senior Project Manager...

JAVA DEVELOPER - BERKSHIRE - TO £34k PLUS PACKAGE

JAVA DEVELOPER TRANSPORT MANAGEMENT SYSTEMS / TMS...

To send to more than one email address, simply separate each address with a comma.