PT-2005-3509 · Autonomy+1 · Autonomy Keyview Sdk+1
Publicado
2005-12-31
·
Atualizado
2018-10-19
·
CVE-2005-2619
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Autonomy KeyView SDK versions prior to 9.2.0
Lotus Notes versions 6.5.4 and 7.0
Description
The issue allows remote attackers to delete arbitrary files by exploiting a directory traversal vulnerability. This can be achieved through a ZIP, UUE, or TAR archive containing a .. (dot dot) in the filename, which is not properly handled when generating a preview.
Recommendations
For Autonomy KeyView SDK versions prior to 9.2.0, update to version 9.2.0 or later.
For Lotus Notes versions 6.5.4 and 7.0, consider restricting access to the KeyView SDK functionality until a patch or update is available.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autonomy Keyview Sdk
Lotus Notes