Vulnerability CVE-2011-1512


Published: 2011-05-31   Modified: 2012-02-13

Description:
Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.

See advisories in our WLB2 database:
Topic
Author
Date
High
Lotus Notes XLS viewer malformed BIFF record heap overflow
CORE
02.06.2011

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

Vendor: IBM
Product: Lotus notes 
Version:
8.5.2.2
8.5.2.1
8.5.2.0
8.5.1.5
8.5.1.4
8.5.1.3
8.5.1.2
8.5.1.1
8.5.1.0
8.5.1
8.5.0.1
8.5.0.0
8.5
8.0.2.6
8.0.2.5
8.0.2.4
8.0.2.3
8.0.2.2
8.0.2.1
8.0.2.0
8.0.2
8.0.1
8.0.0
8.0
7.0.4.2
7.0.4.1
7.0.4.0
7.0.4
7.0.3.1
7.0.3
7.0.2.3
7.0.2.2
7.0.2.1
7.0.2
7.0.1.1
7.0.1
7.0.0
7.0
6.5.6.3
6.5.6.2
6.5.6.1
6.5.6
6.5.5.3
6.5.5.2
6.5.5.1
6.5.5
6.5.4.3
6.5.4.2
6.5.4.1
6.5.4
6.5.3.1
6.5.3
6.5.2
6.5.1
6.5
6.0.5
6.0.4
6.0.3
6.0.2.2
6.0.2
6.0.1
6.0
5.0a
5.02
5.0.9a
5.0.9
5.0.8
5.0.7a
5.0.7
5.0.6a.01
5.0.6a
5.0.6
5.0.5.02
5.0.5.01
5.0.5
5.0.4a
5.0.4
5.0.3
5.0.2c
5.0.2b
5.0.2a
5.0.2
5.0.1c
5.0.1b
5.0.1a
5.0.12
5.0.11
5.0.10
5.0.1.02
5.0.1
5.0
4.6.7h
4.6.7a
4.6
4.5
4.2.2
4.2.1
4.2
3.0.0.2
3.0.0.1
See more versions on NVD

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://securityreason.com/securityalert/8263
http://www.coresecurity.com/content/LotusNotes-XLS-viewer-heap-overflow
http://www.ibm.com/support/docview.wss?uid=swg21500034
http://www.securityfocus.com/archive/1/518120/100/0/threaded
http://www.securityfocus.com/bid/47962
https://exchange.xforce.ibmcloud.com/vulnerabilities/67619
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14203

Related CVE
CVE-2019-4384
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 16217...
CVE-2019-4364
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
CVE-2019-4303
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2019-4142
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.
CVE-2019-4177
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158882.
CVE-2019-4176
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the sy...
CVE-2019-4174
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158879.
CVE-2019-4173
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP OPTIONS method, aka Optionsbleed. By sending an OPTIONS HTTP request, a remote attacker could...

Copyright 2019, cxsecurity.com

 

Back to Top