Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > ÓʼþÈí¼þ©¶´ > IBMȺ¼¯Æ½Ì¨´¦ÀíHTTPÍ·´úÂë´æÔÚÕ»Òç³ö©¶´ > ÕýÎÄ

IBMȺ¼¯Æ½Ì¨´¦ÀíHTTPÍ·´úÂë´æÔÚÕ»Òç³ö©¶´

³ö´¦£ºÂÌÃ˿Ƽ¼ ×÷ÕߣºÂÌÃ˿Ƽ¼ ʱ¼ä£º2008-6-1 23:27:03
Lotus DominoÊǼ¯µç×ÓÓʼþ¡¢ÎĵµÊý¾Ý¿â¡¢¿ìËÙÓ¦Óÿª·¢¼¼ÊõÒÔ¼°Web¼¼ÊõΪһÌåµÄµç×ÓÓʼþÓëȺ¼¯Æ½Ì¨¡£

·¢²¼ÈÕÆÚ£º2008-05-20

¸üÐÂÈÕÆÚ£º2008-05-22

ÊÜÓ°Ïìϵͳ£º

IBM Lotus Domino 8.0

IBM Lotus Domino 7.0

IBM Lotus Domino 6.5

IBM Lotus Domino 6.0

IBM Lotus Domino

ÃèÊö£º

----------------------------------------------------------------------------

BUGTRAQ ID: 29310

CVE(CAN) ID: CVE-2008-2240

Lotus DominoÊǼ¯µç×ÓÓʼþ¡¢ÎĵµÊý¾Ý¿â¡¢¿ìËÙÓ¦Óÿª·¢¼¼ÊõÒÔ¼°Web¼¼ÊõΪһÌåµÄµç×ÓÓʼþÓëȺ¼¯Æ½Ì¨¡£

Lotus Domino Web·þÎñÆ÷ÖиºÔð´¦ÀíHTTPÍ·µÄ´úÂë´æÔÚÕ»Òç³ö©¶´£¬Accept Language×Ö¶ÎÊÇÖ±½Ó´ÓÇëÇóµÄHTTPÍ·ÖлñµÃµÄ£¬È»ºóʹÓÃstrcpyº¯Êý¿½±´µ½Á˹̶¨³¤¶ÈµÄÕ»»º³åÇøÖУ¬Òò´ËÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý°üº¬ÓÐGET·½Ê½µÄHTTP 1.1ÇëÇ󸲸ÇÕ»»º³åÇø£¬µ¼ÖÂÖ´ÐÐÈÎÒâÖ¸Áî¡£

<*À´Ô´£ºM. Ruks

Á´½Ó£ºhttp://secunia.com/advisories/30310/

http://www-1.ibm.com/support/docview.wss?uid=swg21303057

http://www.mwrinfosecurity.com/publications/mwri_ibm-lotus-domino-accept-

language-stack-overflow_2008-05-20.pdf

http://secunia.com/advisories/30332/

*>

½¨Ò飺

----------------------------------------------------------------------------

³§É̲¹¶¡£º

IBM

---

Ŀǰ³§ÉÌÒѾ­·¢²¼ÁËÉý¼¶²¹¶¡ÒÔÐÞ¸´Õâ¸ö°²È«ÎÊÌ⣬Çëµ½³§É̵ÄÖ÷Ò³ÏÂÔØ£º

http://www.ers.ibm.com/

Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • IBM Lotus Quickr¶à¸ö¿çÕ¾½Å±¾Ö´ÐЩ¶´
  • IBM Lotus Domino Óʼþ·þÎñÆ÷ÅäÖù¥ÂÔ
  • IBM Lotus Domino ServerÊ×´ÎÅäÖÃÏê½â
  • IBM/VMwareר¼Ò¹¥ÆÆVistaÄÚ´æ±£»¤
  • ר¼Ò·Ã̸: Stephen Hardison̸IBM Lotus
  • IBM Lotus Sametime StMux.exe·þÎñÕ»Òç³ö©¶´
  • IBMÄ«Î÷¸ç¹éµµ½â¾ö·½°¸ÖÐÐÄÁÁÏà
  • IBM LotusÌ×¼þµÇ½ºÚÝ®ÊÖ»ú ºÅ³ÆÒµ½çÎÞµÐ×éºÏ
  • IBM·¢²¼×îÐÂÈí¼þLotus Quickr 8.1
  • IBMÊ×´ÎÍÆ³öSaaS´æ´¢·þÎñ
  • ÊÕDigitalºó IBMÍÆÔÚÏß´æ´¢·þÎñ
  • IBM¹«²¼08ÄêLotus·Ïßͼ
  • Exchange Server 2003 ÖеÄÈõµã»áµ¼ÖÂȨÏÞÌáÉý
  • ¸ü°²È«Îȶ¨!¿ìÏÂÔØÎ¢ÈíISA 2000 SP2
  • MDaemon 7.2·¢ÏÖȨÏÞÌáÉý©¶´
  • Exchange 2003 Server·¢²¼Ð²¹¶¡KB883543
  • ΢Èí·¢²¼¹ØÓÚExchange©¶´½ô¼±¹«¸æ
  • MS05-021:Exchange Server©¶´Ô¶³ÌÖ´ÐдúÂë
  • WebAdmin 3.0.2 ¿çÕ¾½Å±¾¡¢HTML×¢È밲ȫ©¶´
  • Imail Server IMAP EXAMINEÃüÁ³åÇøÒç³ö©¶´
  • Open WebMail Email´æÔÚÍ·×Ö¶ÎHTML´úÂë×¢Èë©¶´
  • ΢Èí·¢²¼¹ØÓÚExchange 5.5 ©¶´¸üй«¸æ
  • IMail 8.13Ô¶³ÌDELETEÃüÁ³åÇøÒç³ö©¶´
  • MS04-035:SMTPÖа²È«Â©¶´¿ÉÄÜÔÊÐíÖ´ÐÐÔ¶³Ì´úÂë
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ