CVE-2008-4564
Summary
| CVE | CVE-2008-4564 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-18 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Autonomy | Keyview Export Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Export Sdk | All | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Filter Sdk | All | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 10.3 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | 9.2.0 | All | All | All |
| Application | Autonomy | Keyview Viewer Sdk | All | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.12 | All | All | All |
| Application | Ibm | Lotus Notes | 5.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.0.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 6.5.5 | All | fp3 | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.6 | All | fp2 | All |
| Application | Ibm | Lotus Notes | 7.0 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.1 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | All | All |
| Application | Ibm | Lotus Notes | 7.0.2 | All | fp1 | All |
| Application | Ibm | Lotus Notes | 7.0.3 | All | All | All |
| Application | Ibm | Lotus Notes | 8.0 | All | All | All |
| Application | Symantec | Altiris Deployment Solution | All | All | All | All |
| Application | Symantec | Brightmail | 5.0 | All | appliance | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 7.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | linux | All |
| Application | Symantec | Data Loss Prevention Detection Servers | 8.1 | All | windows | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.0 | All | All | All |
| Application | Symantec | Data Loss Prevention Endpoint Agents | 8.1 | All | All | All |
| Application | Symantec | Enforce | 7.0 | All | All | All |
| Application | Symantec | Enforce | 8.0 | All | All | All |
| Application | Symantec | Enforce | 8.1 | All | linux | All |
| Application | Symantec | Enforce | 8.1 | All | windows | All |
| Application | Symantec | Mail Security | 5.0 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.0 | All | All | All |
| Application | Symantec | Mail Security | 5.0.0 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.0.24 | All | appliance | All |
| Application | Symantec | Mail Security | 5.0.1 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.181 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.182 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.189 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.1.200 | All | smtp | All |
| Application | Symantec | Mail Security | 5.0.10 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 5.0.11 | All | microsoft_exchange | All |
| Application | Symantec | Mail Security | 6.0.6 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 6.0.7 | microsoft_exchange | All | All |
| Application | Symantec | Mail Security | 7.5..4.29 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.3.25 | All | domino | All |
| Application | Symantec | Mail Security | 7.5.5.32 | All | domino | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Autonomy KeyView SDK "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityTracker.com Archives - Symantec Data Loss Prevention Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Customer Support Site Login | HP Autonomy | af854a3a-2127-422b-91ae-364da2661108 | customers.autonomy.com | |
| Symantec Security Advisory | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Vendor Advisory |
| 504 Gateway Time-out | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerability Note VU#276563 - Autonomy KeyView SDK buffer overflow vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM - Potential security issue with Lotus Notes file viewer for WordPerfect | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| osvdb.org/52713 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM Lotus Notes Buffer Overflows in File Viewer for WordPerfect Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Lotus Notes File Viewer "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityTracker.com Archives - Symantec Mail Security Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Lotus Notes 6 File Viewer "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| labs.idefense.com/intelligence/vulnerabilities/display.php | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | |
| Symantec Products KeyView "wp6sr.dll" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.