Required CVE Record Information
Description
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.
References 17 Total
- securityreason.com: 3357 third-party-advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-059.html
- http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111
- securitytracker.com: 1018853 vdb-entry
- securityfocus.com: 20071023 [vuln.sg] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities mailing-list
- vupen.com: ADV-2007-3697 vdb-entry
- securityfocus.com: 26175 vdb-entry
- http://vuln.sg/lotusnotes702sam-en.html
- http://vuln.sg/lotusnotes702mif-en.html
- securityfocus.com: 20071031 ZDI-07-059: Verity KeyView SDK Multiple File Format Parsing Vulnerabilities mailing-list
- secunia.com: 27304 third-party-advisory
- http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836
- http://vuln.sg/lotusnotes702-en.html
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html
- securitytracker.com: 1018886 vdb-entry
- vupen.com: ADV-2007-3596 vdb-entry
- http://vuln.sg/lotusnotes702doc-en.html
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 17 Total
- securityreason.com: 3357 third-party-advisoryx_transferred
- http://www.zerodayinitiative.com/advisories/ZDI-07-059.html x_transferred
- http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111 x_transferred
- securitytracker.com: 1018853 vdb-entryx_transferred
- securityfocus.com: 20071023 [vuln.sg] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities mailing-listx_transferred
- vupen.com: ADV-2007-3697 vdb-entryx_transferred
- securityfocus.com: 26175 vdb-entryx_transferred
- http://vuln.sg/lotusnotes702sam-en.html x_transferred
- http://vuln.sg/lotusnotes702mif-en.html x_transferred
- securityfocus.com: 20071031 ZDI-07-059: Verity KeyView SDK Multiple File Format Parsing Vulnerabilities mailing-listx_transferred
- secunia.com: 27304 third-party-advisoryx_transferred
- http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836 x_transferred
- http://vuln.sg/lotusnotes702-en.html x_transferred
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html x_transferred
- securitytracker.com: 1018886 vdb-entryx_transferred
- vupen.com: ADV-2007-3596 vdb-entryx_transferred
- http://vuln.sg/lotusnotes702doc-en.html x_transferred