PT-2011-3179 · Autonomy+1 · Autonomy Keyview+2

Nadia Rodriguez

+2

·

Publicado

2011-05-31

·

Atualizado

2018-10-09

·

CVE-2011-1512

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Lotus Notes versions prior to 8.5.2 FP3
Description The issue is related to a heap-based buffer overflow in the xlssr.dll component of Autonomy KeyView, used in IBM Lotus Notes. This can be exploited by remote attackers through a malformed BIFF record in a .xls Excel spreadsheet attachment, potentially allowing the execution of arbitrary code.
Recommendations For versions prior to 8.5.2 FP3, update to version 8.5.2 FP3 or later to resolve the issue. As a temporary workaround, consider restricting the handling of .xls attachments in IBM Lotus Notes until the update is applied.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1512

Produtos afetados

Autonomy Keyview
Ibm Lotus Notes
Xlssr.Dll