First published: Fri Mar 05 2010(Updated: )
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Data Loss Prevention | =9.0.1 | |
Symantec Mail Security | =8.0.2 | |
Symantec Identity Manager | ||
Symantec Mail Security | =6.0.7 | |
Symantec Mail Security | =7.5.7 | |
Symantec Mail Security | =6.0.6 | |
IBM Lotus Notes | =8.5 | |
Symantec Data Loss Prevention | =10.0 | |
Symantec Mail Security | =5.0.13 | |
Symantec Mail Security | =8.0.1 | |
Symantec Data Loss Prevention | =8.1.1 | |
Symantec Mail Security | =7.5.6 | |
Symantec Mail Security | =5.0.1.181 | |
Symantec Mail Security | =7.5.3.25 | |
Symantec Mail Security | =5.0.11 | |
Symantec Data Loss Prevention | =8.1.1 | |
Symantec Data Loss Prevention | =10.0 | |
Symantec Data Loss Prevention | =9.0.1 | |
Symantec Mail Security | =6.0.8 | |
Symantec Mail Security | =5.0.12 | |
Symantec Brightmail Gateway | =8.0 | |
Symantec Mail Security | =5.0.1.182 | |
Symantec Data Loss Prevention | =8.1.1 | |
Symantec Mail Security | =7.5.5.32 | |
Symantec Mail Security | =7.5.8 | |
Symantec Mail Security | =5.0.1.189 | |
Symantec Mail Security | =7.5.4.29 | |
Symantec Data Loss Prevention | =10.0 | |
Symantec Mail Security | =8.0 | |
Symantec Mail Security | =5.0.0 | |
Symantec Data Loss Prevention | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3032 has a critical severity rating due to its potential to allow arbitrary code execution by attackers.
To fix CVE-2009-3032, update the affected software to the latest version where the vulnerability is patched.
CVE-2009-3032 affects products such as IBM Lotus Notes 8.5 and various versions of Symantec Mail Security.
CVE-2009-3032 is an integer overflow vulnerability that can be exploited through crafted OLE documents.
Yes, CVE-2009-3032 can be exploited remotely by an attacker via a specially crafted document.