HCL
Skip to main content  
 
   


SPRTechnote


IBM Lotus Domino tunekrnl overflow vulnerabilities

Technote Number: 1249173


Problem:
This issue was reported to Quality Engineering as SPR# KEMG6SRKEM and has been
fixed in Domino 6.5.5 Fix Pack 2 (FP2) and Domino 7.0.2.

To work around this issue in previous affected releases, the tunekrnl binary
file can be renamed or deleted or the set-user-id bit can be removed. This
will prevent exploitation of the vulnerability, but it will also cause the loss
of some tuneable setting changes which affect the performance of Domino.

Additional Information:
Attack vector: Local system
Impact: Privilege escalation
Mitigating factors:
File can be removed as a workaround
Requires local system access to exploit
More >





  Document options
Print this document
Print view

  Search
Search Advanced Search


  Fix list views

 RSS feeds   RSS
Subscribe to the fix list

  Resources
Using this database
View notices

  HCL Support
HCL Support


    About HCL Privacy Contact