int(4538)

Vulnerability Bulletins


Ejecución remota de código en Autonomy KeyView

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Comercial Software
Affected software Autonomy KeyView SDK <= 10.4
Symantec Mail Security for SMTP 5.0.1 Patch 200
Symantec Mail Security for SMTP 5.0.1 Patch 189
Symantec Mail Security for SMTP 5.0.1 Patch 182
Symantec Mail Security for SMTP 5.0.1 Patch 181
Symantec Mail Security for SMTP 5.0.1
Symantec Mail Security for SMTP 5.0
Symantec Mail Security for Microsoft Exchange 6.0.7
Symantec Mail Security for Microsoft Exchange 6.0.6
Symantec Mail Security for Microsoft Exchange 5.0.11
Symantec Mail Security for Microsoft Exchange 5.0.10
Symantec Mail Security for Domino 7.5.5 32
Symantec Mail Security for Domino 7.5.4 29
Symantec Mail Security for Domino 7.5.3.25
Symantec Mail Security Appliance 5.0
Symantec Mail Security Appliance 5.0.0.24
Symantec Mail Security Appliance 5.0.0-36
Symantec Mail Security Appliance 5.0.0-36
Symantec Enforce for Windows 8.1
Symantec Enforce for Linux 8.1
Symantec Enforce 8.0
Symantec Enforce 7.0
Symantec Data Loss Prevention Endpoint Agents 8.1
Symantec Data Loss Prevention Endpoint Agents 8.0
Symantec Data Loss Prevention Detection Servers for Windows 8.1
Symantec Data Loss Prevention Detection Servers for Linux 8.1
Symantec Data Loss Prevention Detection Servers 8.0
Symantec Data Loss Prevention Detection Servers 7.0
Symantec BrightMail Appliance 5.0

Description

Se ha descubierto una vulnerabilidad de tipo desbordamiento de pila en Symantec Autonomy KeyView SDK 10.4. La vulnerabilidad reside en un error en la librería wp6sr.dll.

Un atacante remoto podría ejecutar código arbitrario mediante un fichero Word Perfect Document especialmente diseñado.

Solution



Actualización de software

Symantec (SYM09-004)
Consultar tabla de productos afectados en
http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17a.html
http://kb.altiris.com/

Standar resources

Property Value
CVE CVE-2008-4564
BID 34086

Other resources

Symantec Security Advisory (SYM09-004)
http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17a.html

Version history

Version Comments Date
1.0 Aviso emitido 2009-03-20