First published: Sat Nov 10 2007(Updated: )
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Mail Security | =5.0.1 | |
IBM Lotus Notes | <=7.0.2 | |
Autonomy Keyview Viewer Sdk | <=9.2.0 | |
Symantec Mail Security | =5.0.0.24 | |
Symantec Mail Security | =7.5 | |
ActivePDF DocConverter | =3.8.2_.5 | |
Symantec Mail Security | =5.0 | |
Autonomy Keyview Filter Sdk | <=9.2.0 | |
Autonomy Keyview Export Sdk | <=9.2.0 | |
Symantec Mail Security | =5.0 | |
Symantec Mail Security | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.