漏洞信息详情
Autonomy KeyView模块Applix图形阅读器 缓冲区溢出漏洞
漏洞简介
KeyView是用于导出、转换和查看各种格式文件的软件包。
Applix图形阅读器(kpagrdr.dll)在解析*BEGIN标签的ENCODING属性时没有安全地调用sscanf(),可能导致栈溢出,在解析输入文件的超长令牌时存在堆溢出,还可能出现死循环。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.autonomy.com/content/Products/KeyView/index.en.html
参考网址
来源: XF
名称: autonomy-keyview-applix-multiple-bo(41721)
链接:http://xforce.iss.net/xforce/xfdb/41721
来源: www.symantec.com
链接:http://www.symantec.com/avcenter/security/Content/2008.04.08e.html
来源: SECTRACK
名称: 1019844
链接:http://www.securitytracker.com/id?1019844
来源: BID
名称: 28454
链接:http://www.securityfocus.com/bid/28454
来源: BUGTRAQ
名称: 20080414 Secunia Research: activePDF DocConverter Applix Graphics ParsingVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/490839/100/0/threaded
来源: BUGTRAQ
名称: 20080414 Secunia Research: Symantec Mail Security Applix Graphics ParsingVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/490838/100/0/threaded
来源: BUGTRAQ
名称: 20080414 Secunia Research: Autonomy Keyview Applix Graphics ParsingVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/490837/100/0/threaded
来源: BUGTRAQ
名称: 20080414 Secunia Research: Lotus Notes Applix Graphics ParsingVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/490825/100/0/threaded
来源: VUPEN
名称: ADV-2008-1156
链接:http://www.frsirt.com/english/advisories/2008/1156
来源: VUPEN
名称: ADV-2008-1154
链接:http://www.frsirt.com/english/advisories/2008/1154
来源: VUPEN
名称: ADV-2008-1153
链接:http://www.frsirt.com/english/advisories/2008/1153
来源: www-1.ibm.com
链接:http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21298453
来源: SECTRACK
名称: 1019805
链接:http://securitytracker.com/id?1019805
来源: MISC
链接:http://secunia.com/secunia_research/2007-98/advisory/
来源: MISC
链接:http://secunia.com/secunia_research/2007-97/advisory/
来源: MISC
链接:http://secunia.com/secunia_research/2007-96/advisory/
来源: MISC
链接:http://secunia.com/secunia_research/2007-95/advisory/
来源: SECUNIA
名称: 29342
链接:http://secunia.com/advisories/29342
来源: SECUNIA
名称: 28210
链接:http://secunia.com/advisories/28210
来源: SECUNIA
名称: 28209
链接:http://secunia.com/advisories/28209
来源: SECUNIA
名称: 28140
链接:http://secunia.com/advisories/28140
来源: SECUNIA
名称: 27763
链接:http://secunia.com/advisories/27763
受影响实体
- Activepdf Docconverter:3.8.2_.5<!--2000-1-1-->
- Activepdf Docconverter:3.8.4.0<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...