PT-2010-3200 · Ibm+1 · Spreadsheet Lotus 123+1

Publicado

2010-08-17

·

Atualizado

2013-02-07

·

CVE-2010-1525

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autonomy KeyView versions 10.4 through 10.9
Description The issue is related to an integer underflow in the SpreadSheet Lotus 123 reader, which can lead to a denial of service or potentially allow the execution of arbitrary code. This is caused by a crafted size for an unspecified record type, resulting in a heap-based buffer overflow.
Recommendations For Autonomy KeyView versions 10.4 through 10.9, consider disabling the SpreadSheet Lotus 123 reader (wkssr.dll) as a temporary workaround to minimize the risk of exploitation. Restrict access to the affected module to prevent potential attacks until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1525

Produtos afetados

Autonomy Keyview
Spreadsheet Lotus 123