PT-2008-1479 · Autonomy · Autonomy Keyview

Publicado

2008-04-10

·

Atualizado

2018-10-15

·

CVE-2007-5399

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autonomy KeyView versions 10.3.0.0
Description The issue is related to multiple heap-based buffer overflows in the EML reader of Autonomy KeyView, which can be exploited by remote attackers to execute arbitrary code. This can be achieved through various means, including:
  • a long string in the To, Cc, Bcc, From, Date, Subject, Priority, Importance, or X-MSMail-Priority header,
  • a long string at the beginning of an RFC2047 encoded-word in a header,
  • a long text string in an RFC2047 encoded-word in a header,
  • or a long Subject header.
Recommendations For Autonomy KeyView version 10.3.0.0, consider disabling the EML reader functionality until a patch is available to prevent exploitation. Restrict access to the emlsr.dll module to minimize the risk of arbitrary code execution. Avoid using long strings in headers and encoded-words to reduce the risk of buffer overflows.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5399

Produtos afetados

Autonomy Keyview