Secunia CSI 5.0
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA16100

Verity KeyView SDK Multiple Vulnerabilities
Secunia Advisory SA16100
Get alerted and manage the vulnerability life cycle
Free Trial

Release Date 2006-02-10
Last Update 2006-02-20
   
Popularity 10,413 views
Comments 0 comments

Criticality level Highly criticalHighly critical
Impact Security Bypass
System access
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
   
Software:
Verity KeyView Export SDK 7.x
Verity KeyView Export SDK 8.x
Verity KeyView Export SDK 9.x
Verity KeyView Filter SDK 7.x
Verity KeyView Filter SDK 8.x
Verity KeyView Filter SDK 9.x
Verity KeyView Viewer SDK 7.x
Verity KeyView Viewer SDK 8.x
Verity KeyView Viewer SDK 9.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2005-2618 CVSS available in Customer Area
CVE-2005-2619 CVSS available in Customer Area
  

Description

Secunia Research has discovered multiple vulnerabilities in Verity KeyView SDK, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.

1) A boundary error in kvarcve.dll when constructing the full pathname of a compressed file to check for its existence before extracting it from a ZIP archive can be exploited to cause a stack-based buffer overflow.

Successful exploitation allows execution of arbitrary code when a compressed file with a long filename is extracted from within an application using the vulnerable viewer.

2) A boundary error in uudrdr.dll when handling UUE files containing an encoded file with an overly long filename can be exploited to cause a stack-based buffer overflow.

Successful exploitation allows execution of arbitrary code when a malicious UUE file is opened in an application using the vulnerable viewer.

3) Directory traversal errors in kvarcve.dll when generating the preview of a compressed file from ZIP, UUE, and TAR archives can be exploited to delete arbitrary files on an affected system.

Successful exploitation requires that a compressed file with directory traversal sequences in its filename is viewed in an application using the vulnerable viewer.

4) A boundary error in the TAR reader (tarrdr.dll) when extracting files from a TAR archive can be exploited to cause a stack-based buffer overflow via a TAR archive containing a file with a long filename.

Successful exploitation allows execution of arbitrary code, but requires that a compressed file within a malicious TAR archive is extracted with an application using the vulnerable viewer.

5) A boundary error in the HTML speed reader (htmsr.dll) can be exploited to cause a stack-based buffer overflow via a malicious HTML document containing an overly long link beginning with either "http", "ftp", or "//".

Successful exploitation allows execution of arbitrary code, but requires that the link in the HTML document is followed in an application using the vulnerable viewer.

6) A boundary error in the HTML speed reader when checking if a link references a local file can be exploited to cause a stack-based buffer overflow via a malicious HTML document containing a specially crafted, overly long link.

Successful exploitation allows execution of arbitrary code as soon as the the malicious HTML document is viewed in an application using the vulnerable viewer.

The vendor reports that all versions prior to 9.2.0 are affected. Four of the vulnerabilities only affect KeyView Viewer SDK, whereas the remaining two vulnerabilities affect the KeyView Filter, Export, and Viewer SDK.


Solution
Update to version 9.2.0 or later.

Provided and/or discovered by
1-2) Tan Chew Keong, Secunia Research.
3) Tan Chew Keong and Carsten Eiram, Secunia Research.
4-6) Carsten Eiram, Secunia Research.

Changelog
Further details available in Customer Area

Original Advisory
Secunia Research:
http://secunia.com/secunia_research/2005-66/

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Verity KeyView SDK Multiple Vulnerabilities
 
No posts yet

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability