PT-2007-6843 · Activepdf+4 · Activepdf Docconverter+4

Publicado

2007-11-10

·

Atualizado

2011-03-08

·

CVE-2007-5910

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autonomy KeyView Viewer, Filter, and Export SDK versions prior to 9.2.0.12 ActivePDF DocConverter (affected versions not specified) IBM Lotus Notes versions prior to 7.0.3 and version 8.0 Symantec Mail Security (affected versions not specified)
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
Recommendations For Autonomy KeyView Viewer, Filter, and Export SDK, update to version 9.2.0.12 or later. For ActivePDF DocConverter, at the moment, there is no information about a newer version that contains a fix for this issue. For IBM Lotus Notes, update to version 7.0.3 or later, and avoid using version 8.0 until a fix is available. For Symantec Mail Security, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5910

Produtos afetados

Activepdf Docconverter
Autonomy Keyview
Ibm Lotus Notes
Symantec Mail Security
Wordperfect