PT-2007-6843 · Activepdf+4 · Activepdf Docconverter+4
Publicado
2007-11-10
·
Atualizado
2011-03-08
·
CVE-2007-5910
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Autonomy KeyView Viewer, Filter, and Export SDK versions prior to 9.2.0.12
ActivePDF DocConverter (affected versions not specified)
IBM Lotus Notes versions prior to 7.0.3 and version 8.0
Symantec Mail Security (affected versions not specified)
Description
The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
Recommendations
For Autonomy KeyView Viewer, Filter, and Export SDK, update to version 9.2.0.12 or later.
For ActivePDF DocConverter, at the moment, there is no information about a newer version that contains a fix for this issue.
For IBM Lotus Notes, update to version 7.0.3 or later, and avoid using version 8.0 until a fix is available.
For Symantec Mail Security, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Activepdf Docconverter
Autonomy Keyview
Ibm Lotus Notes
Symantec Mail Security
Wordperfect