Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pablo Santamaria

Pesquisador deCore Security Technologies
#27011de 53,635
9.3CVSS total
Vulnerabilidades · 1
PT-2011-3179
9.3
2011-05-31
Autonomy · Autonomy Keyview · CVE-2011-1512
**Name of the Vulnerable Software and Affected Versions** IBM Lotus Notes versions prior to 8.5.2 FP3 **Description** The issue is related to a heap-based buffer overflow in the xlssr.dll component of Autonomy KeyView, used in IBM Lotus Notes. This can be exploited by remote attackers through a malformed BIFF record in a .xls Excel spreadsheet attachment, potentially allowing the execution of arbitrary code. **Recommendations** For versions prior to 8.5.2 FP3, update to version 8.5.2 FP3 or later to resolve the issue. As a temporary workaround, consider restricting the handling of .xls attachments in IBM Lotus Notes until the update is applied.