Advisories Blog | G5 Cyber Security

Zero Day Initiative Advisory 07-059

Several vulnerabilities exist in the popular Verity KeyView SDK used in many enterprise applications like IBM Lotus Notes. When parsing several different file formats a standard stack overflow occurs allowing a malicious user to gain complete control of the affected machine under the rights of the currently logged in user. The problem lies when copying user supplied data to a stack based buffer without any boundary conditions.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60578/ZDI-07-059.txt

Source: https://packetstormsecurity.com/files/60578/Zero-Day-Initiative-Advisory-07-059.html

Exit mobile version