CVE-2008-4564
Summary
| CVE | CVE-2008-4564 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-18 15:30:00 UTC |
| Updated | 2017-08-08 01:32:00 UTC |
| Description | Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Autonomy | Keyview Export Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | All | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | All | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | All | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.12 | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp3 | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 7.0 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | fp1 | All |
| Application | Ibm | Lotus Notes | 7.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.0 | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.12 | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp3 | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 7.0 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | fp1 | All |
| Application | Ibm | Lotus Notes | 7.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.0 | All | All | All |
| Application | Symantec | Altiris Deployment Solution | All | All | All | All |
| Application | Symantec | Altiris Deployment Solution | All | All | All | All |
| Application | Symantec | Brightmail | 5.0 | All | appliance | All |
| Application | Symantec | Brightmail | 5.0 | All | appliance | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 7.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | linux | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | windows | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 7.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | linux | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | windows | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.1 | All | All | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.1 | All | All | All |
| Application | Symantec | Enforce | 7.0 | All | All | All |
| Application | Symantec | Enforce | 8.0 | All | All | All |
| Application | Symantec | Enforce | 8.1 | All | linux | All |
| Application | Symantec | Enforce | 8.1 | All | windows | All |
| Application | Symantec | Enforce | 7.0 | All | All | All |
| Application | Symantec | Enforce | 8.0 | All | All | All |
| Application | Symantec | Enforce | 8.1 | All | linux | All |
| Application | Symantec | Enforce | 8.1 | All | windows | All |
| Application | Symantec | Mail Security | 5.0 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.0 | All | All | All |
| Application | Symantec | Mail Security | 5.0.0 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.0.24 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.1 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.181 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.182 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.189 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.200 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.10 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 5.0.11 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 6.0.6 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 6.0.7 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 7.5..4.29 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.3.25 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.5.32 | All | domino | All |
| Application | Symantec | Mail Security | 5.0 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.0 | All | All | All |
| Application | Symantec | Mail Security | 5.0.0 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.0.24 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.1 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.181 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.182 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.189 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.200 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.10 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 5.0.11 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 6.0.6 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 6.0.7 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 7.5..4.29 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.3.25 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.5.32 | All | domino | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM Lotus Notes Buffer Overflows in File Viewer for WordPerfect Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Autonomy KeyView SDK "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Symantec Security Advisory | CONFIRM | www.symantec.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - Symantec Mail Security Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Lotus Notes File Viewer "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Vulnerability Note VU#276563 - Autonomy KeyView SDK buffer overflow vulnerability | CERT-VN | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Symantec Products KeyView "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Customer Support Site Login | HP Autonomy | CONFIRM | customers.autonomy.com | |
| SecurityTracker.com Archives - Symantec Data Loss Prevention Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| IBM - Potential security issue with Lotus Notes file viewer for WordPerfect | CONFIRM | www-01.ibm.com | Vendor Advisory |
| 52713 | OSVDB | osvdb.org | |
| 20090317 Autonomy KeyView Word Perfect File Parsing Buffer Overflow Vulnerability | IDEFENSE | labs.idefense.com | |
| Lotus Notes 6 File Viewer "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| 504 Gateway Time-out | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.