Intrusion Prevention

IBM.Lotus.Notes.HTML.Speed.Reader.Long.URL.Buffer.Overflow

Description

This indicates an attack attempt against a stack-based buffer-overflow vulnerability in Autonomy KeyView SDK.
The vulnerability is caused by insufficient checking when the vulnerable software handles some crafted files. It allows a remote attacker to execute arbitrary code via an email containing malicious links which are handled by the HTML speed reader.

Affected Products

IBM Lotus Notes 6.5.4 and 7.0.
Autonomy (formerly Verity) KeyView SDK before 9.2.0
NOTE: Other versions may also be affected.

Impact

System Compromise: Successful exploitation allows execution of arbitrary code.

Recommended Actions

Update to version 6.5.5 or 7.0.1.

CVE References

CVE-2005-2618