First published: Mon Jan 23 2012(Updated: )
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Symphony | <=3.0.0.3 | |
IBM Lotus Symphony | =1.3 | |
IBM Lotus Symphony | =3.0.0.1 | |
IBM Lotus Symphony | =3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0192 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2012-0192, upgrade to IBM Lotus Symphony version 3.0.1 or later.
CVE-2012-0192 can be triggered by JPEG or PNG image objects embedded in a Symphony document.
Users of IBM Lotus Symphony versions prior to 3.0.1 are affected by CVE-2012-0192.
If exploited, CVE-2012-0192 may allow attackers to execute arbitrary code on the victim's system.