PT-2008-1486 · Autonomy · Applix Presents Reader+1
Publicado
2008-04-10
·
Atualizado
2018-10-15
·
CVE-2007-5406
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Applix Presents reader in Autonomy (formerly Verity) KeyView versions 2.0.0.2 through 10.3.0.0
Description
The issue is related to the improper parsing of long tokens by the kpagrdr.dll, which can be exploited by remote attackers to cause a denial of service. This is achieved through a crafted .ag file, leading to CPU and memory consumption.
Recommendations
For versions 2.0.0.2 through 10.3.0.0, consider restricting access to the kpagrdr.dll until a patch is available to prevent the denial of service caused by crafted .ag files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Applix Presents Reader
Keyview