CVE-2010-1525
Autonomy KeyView wkssr.dll Integer Underflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.
Desbordamiento de entero en el lector SpreadSheet Lotus 123 (wkssr.dll) de Autonomy KeyView v10.4 y v10.9, como el usuado en IBM, Symantec, y otros productos, permite a los atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código a su elección a través de tamaños manipulados para un tipo de registro no especificado, lo que dispara un desbordamiento de búfer basados en pila.
Secunia Research has discovered a vulnerability in Autonomy KeyView, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. The vulnerability is caused by an integer underflow error in the SpreadSheet Lotus 123 reader (wkssr.dll) when parsing the size of a specific record type. This can be exploited to cause a heap-based buffer overflow via a specially crafted file. Successful exploitation may allow execution of arbitrary code. Autonomy KeyView versions 10.4 and 10.9 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-04-26 CVE Reserved
- 2010-07-28 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21440812 | X_refsource_confirm | |
http://www.securityfocus.com/bid/41928 | Vdb Entry | |
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/secunia_research/2010-49 | 2013-02-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Autonomy Search vendor "Autonomy" | Keyview Export Sdk Search vendor "Autonomy" for product "Keyview Export Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Export Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Export Sdk Search vendor "Autonomy" for product "Keyview Export Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Export Sdk" and version "10.9" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Filter Sdk Search vendor "Autonomy" for product "Keyview Filter Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Filter Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Filter Sdk Search vendor "Autonomy" for product "Keyview Filter Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Filter Sdk" and version "10.9" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Viewer Sdk Search vendor "Autonomy" for product "Keyview Viewer Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Viewer Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Viewer Sdk Search vendor "Autonomy" for product "Keyview Viewer Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Viewer Sdk" and version "10.9" | - |
Affected
|