CVE-2008-1101
secunia-lotusnotes.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.
Desbordamiento de búfer en el motor del visor de documentos KeyView de Autonomy (anteriormente Verity) KeyView, usado por IBM Lotus Notes 7.0.2 y 7.0.3, permite a atacantes remotos ejecutar código de su elección a través de un nombre de ruta largo, como se ha demostrado usando un atributo SRC largo en una etiqueta IMG de un documento HTML.
Secunia Research has discovered a vulnerability in Lotus Notes, which can be exploited by malicious people to compromise a user's system. A boundary error within kvdocve.dll when processing overly long paths can be exploited to cause a buffer overflow via e.g. an overly long link inside the "src" attribute of antag in an HTML document. Lotus Notes versions 7.0.2 and 7.0.3 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-02-29 CVE Reserved
- 2008-04-10 CVE Published
- 2024-08-07 CVE Updated
- 2025-05-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21298453 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/490826/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/28454 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1153 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1156 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41725 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/28140 | 2018-10-11 | |
http://secunia.com/advisories/28209 | 2018-10-11 | |
http://secunia.com/advisories/28210 | 2018-10-11 | |
http://secunia.com/secunia_research/2008-12/advisory | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Autonomy Search vendor "Autonomy" | Keyview Search vendor "Autonomy" for product "Keyview" | 2.0.0.2 Search vendor "Autonomy" for product "Keyview" and version "2.0.0.2" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Search vendor "Autonomy" for product "Keyview" | 10.3.0.0 Search vendor "Autonomy" for product "Keyview" and version "10.3.0.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Notes Search vendor "Ibm" for product "Lotus Notes" | 6.0 Search vendor "Ibm" for product "Lotus Notes" and version "6.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Notes Search vendor "Ibm" for product "Lotus Notes" | 6.5 Search vendor "Ibm" for product "Lotus Notes" and version "6.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Notes Search vendor "Ibm" for product "Lotus Notes" | 7.0 Search vendor "Ibm" for product "Lotus Notes" and version "7.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Notes Search vendor "Ibm" for product "Lotus Notes" | 7.0.2 Search vendor "Ibm" for product "Lotus Notes" and version "7.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Notes Search vendor "Ibm" for product "Lotus Notes" | 7.0.3 Search vendor "Ibm" for product "Lotus Notes" and version "7.0.3" | - |
Affected
|