Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
BID:38468
Info
Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 38468 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3032 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2010 12:00AM |
| Updated: | Mar 05 2010 08:02AM |
| Credit: | Joshua J. Drake with iDefense Labs |
| Vulnerable: |
Symantec Mail Security For Smtp 5.0.1 Patch 205 Symantec Mail Security For Smtp 5.0.1 Patch 201 Symantec Mail Security For Smtp 5.0.1 Patch 200 Symantec Mail Security For Smtp 5.0.1 Patch 189 Symantec Mail Security For Smtp 5.0.1 Patch 182 Symantec Mail Security For Smtp 5.0.1 Patch 181 Symantec Mail Security For Smtp 5.0.1 Symantec Mail Security For Smtp 5.0 Symantec Mail Security For Microsoft Exchange 6.0.9 Symantec Mail Security For Microsoft Exchange 6.0.8 Symantec Mail Security For Microsoft Exchange 6.0.7 Symantec Mail Security For Microsoft Exchange 6.0.6 Symantec Mail Security For Microsoft Exchange 5.0.13 Symantec Mail Security For Microsoft Exchange 5.0.12 Symantec Mail Security For Microsoft Exchange 5.0.11 Symantec Mail Security For Microsoft Exchange 5.0.10 .382 Symantec Mail Security For Microsoft Exchange 5.0.10 Symantec Mail Security for Domino 8.0.2 Symantec Mail Security for Domino 8.0.1 Symantec Mail Security for Domino 7.5.8 Symantec Mail Security for Domino 7.5.7 Symantec Mail Security for Domino 7.5.6 Symantec Mail Security for Domino 7.5.3 25 Symantec Mail Security for Domino 8.0 Symantec Mail Security for Domino 7.5.5.32 Symantec Mail Security for Domino 7.5.4.29 Symantec Mail Security for Domino 7.5.3.25 Symantec IM Manager 8.4 Symantec IM Manager 8.3 Symantec Data Loss Prevention Endpoint Agents 9.0.2 Symantec Data Loss Prevention Endpoint Agents 8.1 Symantec Data Loss Prevention Endpoint Agents 10.0 Symantec Data Loss Prevention Detection Servers for Windows 9.0.2 Symantec Data Loss Prevention Detection Servers for Windows 8.1.1 Symantec Data Loss Prevention Detection Servers for Windows 10.0 Symantec Data Loss Prevention Detection Servers for Linux 9.0.2 Symantec Data Loss Prevention Detection Servers for Linux 8.1.1 Symantec Data Loss Prevention Detection Servers for Linux 10.0 Symantec Data Loss Prevention Detection Servers 7.2 37 Symantec Data Loss Prevention Detection Servers 7.2 Symantec Brightmail Gateway 8.0.2 Symantec Brightmail Gateway 8.0.1 Symantec Brightmail Gateway 8.0 IBM Lotus Notes 8.5 |
| Not Vulnerable: |
Symantec Mail Security For Microsoft Exchange 6.0.10 Symantec Mail Security for Domino 8.0.3 Symantec Mail Security for Domino 7.5.9 Symantec IM Manager 8.4.13 Symantec Data Loss Prevention Endpoint Agents 10.0.1010 .18007 Symantec Data Loss Prevention Endpoint Agents 8.1.10 .9 Symantec Data Loss Prevention Endpoint Agents 9.0.3 Symantec Data Loss Prevention Detection Servers for Windows 10.0.1010 .18007 Symantec Data Loss Prevention Detection Servers for Windows 9.0.3 Symantec Data Loss Prevention Detection Servers for Windows 8.1.10 .8 Symantec Data Loss Prevention Detection Servers for Linux 10.0.1010 .18007 Symantec Data Loss Prevention Detection Servers for Linux 9.0.3 Symantec Data Loss Prevention Detection Servers for Linux 8.1.10 .8 Symantec Data Loss Prevention Detection Servers 7.2 .40 Symantec Brightmail Gateway 9.0 |
Discussion
Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
Autonomy KeyView module is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting this issue will allow an attacker to corrupt memory and cause denial-of-service conditions and may potentially allow the execution of arbitrary code in the context of an application using the module.
Multiple products using the KeyView module are affected, including:
Symantec Mail Security for Domino
Symantec Mail Security for Microsoft Exchange
Symantec Mail Security for SMTP
Symantec Brightmail Gateway
Symantec Data Loss Prevention Detection Servers
Symantec Data Loss Prevention Endpoint Agents
Symantec IM Manager
Autonomy KeyView module is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting this issue will allow an attacker to corrupt memory and cause denial-of-service conditions and may potentially allow the execution of arbitrary code in the context of an application using the module.
Multiple products using the KeyView module are affected, including:
Symantec Mail Security for Domino
Symantec Mail Security for Microsoft Exchange
Symantec Mail Security for SMTP
Symantec Brightmail Gateway
Symantec Data Loss Prevention Detection Servers
Symantec Data Loss Prevention Endpoint Agents
Symantec IM Manager
Exploit / POC
Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Autonomy KeyView Module OLE Processing Buffer Overflow Vulnerability
References:
References:
- Autonomy KeyView OLE Document Integer Overflow Vulnerability (iDefense)
- KeyView Homepage (Autonomy)
- Symantec Homepage (Symantec)
- Security Advisories Relating to Symantec Products - Multi-Vendor Autonomy KeyVie (Symantec)