PT-2008-1486 · Autonomy · Applix Presents Reader+1
Published
2008-04-10
·
Updated
2018-10-15
·
CVE-2007-5406
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Applix Presents reader in Autonomy (formerly Verity) KeyView versions 2.0.0.2 through 10.3.0.0
Description
The issue is related to the improper parsing of long tokens by the kpagrdr.dll, which can be exploited by remote attackers to cause a denial of service. This is achieved through a crafted .ag file, leading to CPU and memory consumption.
Recommendations
For versions 2.0.0.2 through 10.3.0.0, consider restricting access to the kpagrdr.dll until a patch is available to prevent the denial of service caused by crafted .ag files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Applix Presents Reader
Keyview