CVE-2007-6593
Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.
- CVSS 2.0
- 8.8 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:N
- EPSS
- 6.30% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/lotus notes
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058680.html
- http://secunia.com/advisories/27835Vendor Advisory
- http://secunia.com/advisories/27836Vendor Advisory
- http://secunia.com/advisories/27849Vendor Advisory
- http://securityreason.com/securityalert/3499
- http://securitytracker.com/id?1019002
- http://www.coresecurity.com/index.php5?action=item&id=2008
- http://www.ibm.com/support/docview.wss?rs=475&uid=swg21285600
- http://www.securityfocus.com/archive/1/484272/100/0/threaded
- http://www.securityfocus.com/bid/26604
- http://www.securitytracker.com/id?1019096
- http://www.vupen.com/english/advisories/2007/4012
- http://www.vupen.com/english/advisories/2007/4020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38645
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058680.html
- http://secunia.com/advisories/27835Vendor Advisory
- http://secunia.com/advisories/27836Vendor Advisory
- http://secunia.com/advisories/27849Vendor Advisory
- http://securityreason.com/securityalert/3499
- http://securitytracker.com/id?1019002
- http://www.coresecurity.com/index.php5?action=item&id=2008
- http://www.ibm.com/support/docview.wss?rs=475&uid=swg21285600
- http://www.securityfocus.com/archive/1/484272/100/0/threaded
- http://www.securityfocus.com/bid/26604
- http://www.securitytracker.com/id?1019096
- http://www.vupen.com/english/advisories/2007/4012
- http://www.vupen.com/english/advisories/2007/4020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38645
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.