Vulnerability Name: | CVE-2010-4551 (CCN-64395) | ||||||||
Assigned: | 2010-12-16 | ||||||||
Published: | 2010-12-16 | ||||||||
Updated: | 2010-12-17 | ||||||||
Summary: | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation. Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference' | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-4551 Source: CCN Type: IBM APAR LO49829 TRAVELER STOPS FUNCTIONING WHEN PROCESSING AN INVITATION Source: AIXAPAR Type: Vendor Advisory LO49829 Source: CCN Type: IBM Web site Lotus Notes Traveler 851 FP3 Release Notes Source: CCN Type: Lotus Notes Traveler 851 FP3 Release Notes Lotus Notes Traveler 851 FP3 Release Notes Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/dominowiki.nsf/dx/Lotus_Notes_Traveler_851_FP3_Release_Notes Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocument Source: CCN Type: OSVDB ID: 69923 IBM Lotus Notes Traveler Person Document Missing Internet ID Field NULL Dereference Remote DoS Source: XF Type: UNKNOWN ibm-lnt-internetidfield-dos(64395) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |