Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2618

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2005-2618
Last Modified 06 Sep 2011 12:00:00
Published 31 Dec 2005 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2005-2618

Summary

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).

Vulnerable Systems

Application

  • Autonomy Keyview Export Sdk

  • Autonomy Keyview Filter Sdk

  • Autonomy Keyview Viewer Sdk

  • Ibm Lotus Notes 6.0.1

  • Ibm Lotus Notes 6.0.2

  • Ibm Lotus Notes 6.0.3

  • Ibm Lotus Notes 6.0.4

  • Ibm Lotus Notes 6.0.5

  • Ibm Lotus Notes 6.5

  • Ibm Lotus Notes 6.5.1

  • Ibm Lotus Notes 6.5.2

  • Ibm Lotus Notes 6.5.3

  • Ibm Lotus Notes 6.5.4

  • Ibm Lotus Notes 7.0


References

CERT-VN - VU#884076

OSVDB - 23068

OSVDB - 23067

OSVDB - 23066

OSVDB - 23065

OSVDB - 23064

CONFIRM - http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229918

SECTRACK - 1015657

SECUNIA - 16280

SECUNIA - 16100

XF - lotus-htmsr-link-bo(24639)

XF - lotus-tarrdr-filename-bo(24638)

XF - lotus-uudrdr-uue-bo(24636)

XF - lotus-kvarcve-filename-bo(24635)

VUPEN - ADV-2006-0501

VUPEN - ADV-2006-0500

BID - 16576

BUGTRAQ - 20060210 Secunia Research: Lotus Notes HTML Speed Reader Link BufferOverflows

BUGTRAQ - 20060210 Secunia Research: Lotus Notes UUE File Handling Buffer Overflow

BUGTRAQ - 20060210 Secunia Research: Lotus Notes TAR Reader File Extraction BufferOverflow

BUGTRAQ - 20060210 Secunia Research: Lotus Notes ZIP File Handling Buffer Overflow

MISC - http://secunia.com/secunia_research/2005-66/advisory/

MISC - http://secunia.com/secunia_research/2005-37/advisory/

MISC - http://secunia.com/secunia_research/2005-36/advisory/

MISC - http://secunia.com/secunia_research/2005-34/advisory/

MISC - http://secunia.com/secunia_research/2005-32/advisory/


Last Updated: 27 May 2016 10:40:34