Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
BID:50006
Info
Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 50006 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0337 CVE-2011-0338 CVE-2011-0339 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2011 12:00AM |
| Updated: | Oct 11 2011 11:00PM |
| Credit: | Secunia Research |
| Vulnerable: |
IBM Lotus Notes 8.5.2 FP2 Autonomy Verity KeyView Viewer SDK 9.0 Autonomy Verity KeyView Viewer SDK 7.0 Autonomy Verity KeyView Filter SDK 9.0 Autonomy Verity KeyView Filter SDK 7.0 Autonomy Verity KeyView Export SDK 9.0 Autonomy Verity KeyView Export SDK 7.0 Autonomy Keyview Viewer SDK 10.3 Autonomy Keyview Filter SDK 10.3 Autonomy Keyview Export SDK 10.3 |
| Not Vulnerable: |
Autonomy Verity KeyView Viewer SDK 9.2 Autonomy Verity KeyView Viewer SDK 7.4 Autonomy Verity KeyView Filter SDK 9.2 Autonomy Verity KeyView Filter SDK 7.4 Autonomy Verity KeyView Export SDK 9.2 Autonomy Verity KeyView Export SDK 7.4 Autonomy Keyview Viewer SDK 10.13 Autonomy Keyview Filter SDK 10.13 Autonomy Keyview Export SDK 10.13 |
Discussion
Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
Autonomy KeyView Filter is prone to multiple remote heap-based buffer-overflow vulnerabilities because of errors that occur when processing certain files.
Remote attackers can exploit these issues by enticing an unsuspecting user to open a maliciously crafted file.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
Autonomy KeyView Filter 10.3 is vulnerable; other versions may also be affected.
This BID is being retired because these issues have been reported in the following BIDs:
49898 Autonomy KeyView Filter QLST Chunk Integer Overflow Vulnerability
49899 Autonomy KeyView Filter 'Text' Chunk Integer Overflow Vulnerability
49900 Autonomy KeyView Filter Text/QLST Chunk Heap Based Buffer Overflow Vulnerability
Autonomy KeyView Filter is prone to multiple remote heap-based buffer-overflow vulnerabilities because of errors that occur when processing certain files.
Remote attackers can exploit these issues by enticing an unsuspecting user to open a maliciously crafted file.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
Autonomy KeyView Filter 10.3 is vulnerable; other versions may also be affected.
This BID is being retired because these issues have been reported in the following BIDs:
49898 Autonomy KeyView Filter QLST Chunk Integer Overflow Vulnerability
49899 Autonomy KeyView Filter 'Text' Chunk Integer Overflow Vulnerability
49900 Autonomy KeyView Filter Text/QLST Chunk Heap Based Buffer Overflow Vulnerability
Exploit / POC
Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Retired: Autonomy KeyView Filter 'jtdsr.dll' Multiple Buffer Overflow Vulnerabilities
References:
References:
- KeyView Homepage (Autonomy)
- Secunia Research: Autonomy Keyview Ichitaro Object Reconstruction Logic Vulnerab (Secunia Research)
- Secunia Research: Autonomy Keyview Ichitaro QLST Integer Overflow Vulnerability (Secunia Research)
- Secunia Research: Autonomy Keyview Ichitaro Text Parsing Buffer Overflow (Secunia Research)