Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-2618
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2618

Description:
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/24639
  http://xforce.iss.net/xforce/xfdb/24635
  http://xforce.iss.net/xforce/xfdb/24638
  http://xforce.iss.net/xforce/xfdb/24636

ST
  1015657

SAID
  Secunia Advisory: SA16100
  Secunia Advisory: SA16280

OSVDB
  23064
  23065
  23066
  23067
  23068

MISC
  http://secunia.com/secunia_research/2005-37/advisory/
  http://secunia.com/secunia_research/2005-36/advisory/
  http://secunia.com/secunia_research/2005-34/advisory/
  http://secunia.com/secunia_research/2005-32/advisory/
  http://secunia.com/secunia_research/2005-66/advisory/

CONFIRM
  http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229918

CERT-VN
  884076

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/424666/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/424692/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/424626/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/424689/100/0/threaded

BID
  16576


Return to the previous page.