2024-12-08 03:06:42 +00:00

280 lines
9.5 KiB
JSON

{
"id": "CVE-2007-5909",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-11-10T02:46:00.000",
"lastModified": "2024-11-21T00:38:55.323",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910."
},
{
"lang": "es",
"value": "M\u00faltiples desbordamientos de b\u00fafer basados en pila en el Autonomy (antiguamente Verity) KeyView Viewer, en el Filter y en el Export SDK anterior al 9.2.0.12, como el utilizado en el ActivePDF DocConverter, en el IBM Lotus Notes anterior al 7.0.3, en el Symantec Mail Security y en otros productos, permiten a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de modificaciones en (1) el fichero AG del kpagrdr.dll, (2) en el fichero AW del awsr.dll, (3) en el fichero DLL o el (4) EXE del exesr.dll, (5) en el fichero DOC del mwsr.dll, (6) en el fichero MIF del mifsr.dll, (7) en el fichero SAM del lasr.dll o (8) en el fichero RTF del rtfsr.dll. NOTA: el vector WPD (wp6sr.dll) se trata en la vulnerabilidad CVE-2007-5910."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"baseScore": 9.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:activepdf:docconverter:3.8.2_.5:*:*:*:*:*:*:*",
"matchCriteriaId": "0D165E31-F294-4F7E-959F-7AFE69AF90A1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autonomy:keyview_export_sdk:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.2.0",
"matchCriteriaId": "872E3116-26DC-492D-94EA-7BE531299FF8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autonomy:keyview_filter_sdk:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.2.0",
"matchCriteriaId": "07FFE40A-6A96-4131-B537-8A4D8C1494AD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autonomy:keyview_viewer_sdk:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.2.0",
"matchCriteriaId": "D9E88061-F0E3-4CA9-8FCE-4B69FE4F3844"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*",
"versionEndIncluding": "7.0.2",
"matchCriteriaId": "F61B72CC-BC8D-40AF-AE72-5A6EEFB53B10"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:5.0:*:appliance:*:*:*:*:*",
"matchCriteriaId": "0648861C-A58E-4103-8720-4480C2F098FF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:*",
"matchCriteriaId": "9608BF57-0D9A-4874-BFDA-C92447FACD70"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:5.0.0:*:smtp:*:*:*:*:*",
"matchCriteriaId": "5E7788BD-652E-4306-AED0-6AE7F9A07836"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:5.0.0.24:*:appliance:*:*:*:*:*",
"matchCriteriaId": "977786AB-A76C-4A1C-8999-BF4A5E08F8BE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:5.0.1:*:smtp:*:*:*:*:*",
"matchCriteriaId": "A8430D5E-A8A7-4724-8A6B-B5E2CA437729"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:mail_security:7.5:*:domino:*:*:*:*:*",
"matchCriteriaId": "7D29BE63-3E26-4136-BAB1-AA3D50BA71F5"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/27304",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/3357",
"source": "cve@mitre.org"
},
{
"url": "http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018853",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018886",
"source": "cve@mitre.org"
},
{
"url": "http://vuln.sg/lotusnotes702-en.html",
"source": "cve@mitre.org"
},
{
"url": "http://vuln.sg/lotusnotes702doc-en.html",
"source": "cve@mitre.org"
},
{
"url": "http://vuln.sg/lotusnotes702mif-en.html",
"source": "cve@mitre.org"
},
{
"url": "http://vuln.sg/lotusnotes702sam-en.html",
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111",
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/482664",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/483102/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26175",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/3596",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3697",
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-07-059.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27304",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/3357",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018853",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018886",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://vuln.sg/lotusnotes702-en.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://vuln.sg/lotusnotes702doc-en.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://vuln.sg/lotusnotes702mif-en.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://vuln.sg/lotusnotes702sam-en.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/482664",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/483102/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26175",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/3596",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3697",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-07-059.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}