Short Name |
SMTP:MAL:LOTUS-APPLIX
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
SMTP
|
Keywords |
IBM Lotus Notes Applix Graphics Parsing Buffer Overflow
|
Release Date |
2010/10/01
|
Update Number |
1784
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
SMTP: IBM Lotus Notes Applix Graphics Parsing Buffer Overflow
This signature detects attempts to exploit a known vulnerability in IBM Lotus Notes Applix. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.
Extended Description
Autonomy KeyView module is prone to multiple stack- and heap-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting these issues will allow an attacker to corrupt memory and to cause denial-of-service conditions or potentially to execute arbitrary code in the context of the application using the module.
Multiple products using the KeyView module are affected.
Affected Products
- ActivePDF DocConverter 3.8.4.0
- Autonomy Keyview Export SDK 10
- Autonomy Keyview Export SDK 10.3.0
- Autonomy Keyview Export SDK 7
- Autonomy Keyview Export SDK 8
- Autonomy Keyview Export SDK 9
- Autonomy Keyview Filter SDK 10
- Autonomy Keyview Filter SDK 10.3.0
- Autonomy Keyview Filter SDK 7
- Autonomy Keyview Filter SDK 8
- Autonomy Keyview Filter SDK 9
- Autonomy Keyview Viewer SDK 10
- Autonomy Keyview Viewer SDK 10.3.0
- Autonomy Keyview Viewer SDK 7
- Autonomy Keyview Viewer SDK 8
- Autonomy Keyview Viewer SDK 9
- IBM Lotus Notes 6.0.0
- IBM Lotus Notes 6.0.1
- IBM Lotus Notes 6.0.2
- IBM Lotus Notes 6.0.3
- IBM Lotus Notes 6.0.4
- IBM Lotus Notes 6.0.5
- IBM Lotus Notes 6.5.0
- IBM Lotus Notes 6.5.1
- IBM Lotus Notes 6.5.2
- IBM Lotus Notes 6.5.3
- IBM Lotus Notes 6.5.4
- IBM Lotus Notes 6.5.5
- IBM Lotus Notes 6.5.5 FP2
- IBM Lotus Notes 6.5.5 FP3
- IBM Lotus Notes 6.5.6
- IBM Lotus Notes 6.5.6 FP2
- IBM Lotus Notes 7.0
- IBM Lotus Notes 7.0.1
- IBM Lotus Notes 7.0.2
- IBM Lotus Notes 7.0.2 FP1
- IBM Lotus Notes 7.0.3
- IBM Lotus Notes 8.0
- Symantec Mail Security Appliance 5.0.0
- Symantec Mail Security Appliance 5.0.0.24
- Symantec Mail Security for Domino 7.5
- Symantec Mail Security for Microsoft Exchange 5.0.0
- Symantec Mail Security for SMTP 5.0
- Symantec Mail Security for SMTP 5.0.1
References