Autonomy KeyView Multiple Buffer Overflow Vulnerabilities

In certain situations when content scanning is enabled for attachments, an attacker needs only to send a malicious file to an unsuspecting victim. Otherwise, the attacker must entice the victim to open a specially crafted .WPD, .SAM, .MIF, or .DOC file.

The researcher responsible for discovering this issue has developed proof-of-concept exploit code, but it is not publicly available; please see the references for details.

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

UPDATE: (February 11, 2008): DSquare Security has developed a working commercial exploit for its D2 Exploitation Pack product. This exploit is not otherwise publicly available or known to be circulating in the wild.


 

Privacy Statement
Copyright 2010, SecurityFocus