CVE-2008-1101
Last modified
CVE-2008-1101 is a vulnerability of currently unknown severity. Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.. EPSS estimates a 5.53% chance of exploitation in the next 30 days.
Description
Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Autonomy | Keyview | 2.0.0.2 |
| Autonomy | Keyview | 10.3.0.0 |
| Ibm | Lotus Notes | 6.0 |
| Ibm | Lotus Notes | 6.5 |
| Ibm | Lotus Notes | 7.0 |
| Ibm | Lotus Notes | 7.0.2 |
| Ibm | Lotus Notes | 7.0.3 |
References
- http://secunia.com/advisories/28140Vendor Advisory
- http://secunia.com/advisories/28209Vendor Advisory
- http://secunia.com/advisories/28210Vendor Advisory
- http://secunia.com/secunia_research/2008-12/advisory/Vendor Advisory
- http://secunia.com/advisories/28140Vendor Advisory
- http://secunia.com/advisories/28209Vendor Advisory
- http://secunia.com/advisories/28210Vendor Advisory
- http://secunia.com/secunia_research/2008-12/advisory/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1101?
How severe is CVE-2008-1101?
How do I fix CVE-2008-1101?
Are you affected by CVE-2008-1101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
