Advisories Blog | G5 Cyber Security

Autonomy KeyView rtfsr.dll RTF Parsing Signedness Error

Secunia Research has discovered a vulnerability in Autonomy KeyView, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused by a signedness error when parsing the argument to the “ls” keyword within a list override table entry in RTF files. This can be exploited to cause a buffer overflow via a specially crafted RTF file. Successful exploitation may allow execution of arbitrary code. Autonomy KeyView versions 10.4 and 10.9 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/92243/secunia-autonomyrtfsigned.txt

Source: https://packetstormsecurity.com/files/92243/Autonomy-KeyView-rtfsr.dll-RTF-Parsing-Signedness-Error.html

Exit mobile version