| Title | Autonomy KeyView の WordPerfect 5.x reader (wosr.dll) におけるヒープベースのバッファオーバーフローの脆弱性 |
|---|---|
| Summary | Autonomy KeyView の WordPerfect 5.x reader (wosr.dll) には、データブロックに関する処理に不備があるため、ヒープベースのバッファオーバーフローの脆弱性が存在します。 |
| Possible impacts | 第三者により、任意のコードを実行される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Aug. 4, 2010, midnight |
| Registration Date | Aug. 24, 2010, 6:42 p.m. |
| Last Update | Aug. 24, 2010, 6:42 p.m. |
| CVSS2.0 : 危険 | |
| Score | 9.3 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| IBM |
| IBM Notes 6.5.x |
| IBM Notes 7.x |
| IBM Notes 8.0.2 FP6 未満 |
| IBM Notes 8.5.1 FP4 未満 |
| シマンテック |
| Symantec Data Loss Prevention Endpoint Agents 10.0 |
| Symantec Data Loss Prevention Endpoint Agents 10.5 |
| Symantec Data Loss Prevention Endpoint Agents 8.1.1 |
| Symantec Data Loss Prevention Endpoint Agents 9.x |
| Symantec Data Loss Prevention Enforce/Detection Servers (linux) 10.0 |
| Symantec Data Loss Prevention Enforce/Detection Servers (linux) 10.5 |
| Symantec Data Loss Prevention Enforce/Detection Servers (linux) 8.1.1 |
| Symantec Data Loss Prevention Enforce/Detection Servers (linux) 9.x |
| Symantec Data Loss Prevention Enforce/Detection Servers (windows) 10.0 |
| Symantec Data Loss Prevention Enforce/Detection Servers (windows) 10.5 |
| Symantec Data Loss Prevention Enforce/Detection Servers (windows) 8.1.1 |
| Symantec Data Loss Prevention Enforce/Detection Servers (windows) 9.x |
| Symantec IM Manager 2007 8.4.x |
| Symantec Mail Security (domino) 7.5.x |
| Symantec Mail Security (domino) 8.0.x |
| Symantec Mail Security (exchange) 6.0.5 およびそれ以降 |
| Symantec Mail Security (exchange) 6.5.0 |
| Symantec Mail Security (smtp) (EOL) 5.0.x |
| Symantec Mail Security Appliance 7.5.0 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2010年08月24日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Heap-based buffer overflow in the WordPerfect 5.x reader (wosr.dll), as used in Autonomy KeyView 10.4 and 10.9 and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to "data blocks." |
|---|---|
| Publication Date | Aug. 18, 2010, 5 a.m. |
| Registration Date | Jan. 29, 2021, 10:56 a.m. |
| Last Update | Nov. 21, 2024, 10:11 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:autonomy:keyview_filter_sdk:10.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:autonomy:keyview_viewer_sdk:10.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:autonomy:keyview_filter_sdk:10.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:autonomy:keyview_export_sdk:10.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:autonomy:keyview_export_sdk:10.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:autonomy:keyview_viewer_sdk:10.9:*:*:*:*:*:*:* | |||||