CVE-2005-2619: Path Traversal
Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2619?
The severity of CVE-2005-2619 is considered high due to its potential to allow remote attackers to delete arbitrary files.
How do I fix CVE-2005-2619?
To fix CVE-2005-2619, upgrade the Autonomy KeyView SDK to version 9.2.0 or later, or apply any security patches provided by the vendor.
Which software is affected by CVE-2005-2619?
CVE-2005-2619 affects IBM Lotus Notes versions 6.0.1 through 7.0 and Autonomy KeyView SDK versions prior to 9.2.0.
Can CVE-2005-2619 be exploited remotely?
Yes, CVE-2005-2619 can be exploited remotely by sending a specially crafted ZIP, UUE, or TAR archive.
What types of attacks can be performed using CVE-2005-2619?
Using CVE-2005-2619, remote attackers could potentially delete arbitrary files on the affected system.