Vulnerability: CVE-2008-1101

Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.


http://www.securityfocus.com/bid/28454
http://www.securityfocus.com/archive/1/490826/100/0/threaded
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21298453
http://secunia.com/secunia_research/2008-12/advisory/
http://secunia.com/advisories/28140
http://secunia.com/advisories/28209
http://secunia.com/advisories/28210
http://www.vupen.com/english/advisories/2008/1153
http://www.vupen.com/english/advisories/2008/1156
https://exchange.xforce.ibmcloud.com/vulnerabilities/41725
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1101


It's possible to leave a comment as registered users to the site, accessing through social, wordpress account or as anonymous users. If you want to leave a comment as an anonymous user you will be notified by email of a possible response only if you enter the email address (optional). The insertion of any data in the comment fields is totally optional. Whoever decides to insert any data accepts the treatment of these last ones for the inherent purposes of the service that is the answer to the comment and the strictly necessary communications.


Leave a Reply