Vissza a www.andrews.hu-ra

    [guru] IBM biztonsagi frissitesek


    DATE: Wed, 25 Aug 2010 11:48:31 +0200
    Lotus Notes termékcsalád:
    -------------------------
    Az Autonomy KeyView Word dokumentum karakterkészlet név kezelési stack buffer
    overflow hibája, valamint a .WK3 dokumentumok kezelésének buffer overflow
    hibái miatt az IBM Lotus Notes Email kliens támadható.
    
    
    --- Begin Message ---
    ZDI-10-156: IBM Lotus Notes Autonomy KeyView Word Parsing Remote Code Execution Vulnerability
    http://www.zerodayinitiative.com/advisories/ZDI-10-156
    August 23, 2010
    
    -- CVSS:
    10, (AV:N/AC:L/Au:N/C:C/I:C/A:C)
    
    -- Affected Vendors:
    IBM
    Autonomy
    
    -- Affected Products:
    IBM Lotus Notes
    Autonomy KeyView
    
    -- TippingPoint(TM) IPS Customer Protection:
    TippingPoint IPS customers have been protected against this
    vulnerability by Digital Vaccine protection filter ID 9609. 
    For further product information on the TippingPoint IPS, visit:
    
        http://www.tippingpoint.com
    
    -- Vulnerability Details:
    This vulnerability allows remote attackers to execute arbitrary code on
    vulnerable installations of IBM Lotus Notes Email Client. User
    interaction is required to exploit this vulnerability in that the target
    must open a malicious email attachment.
    
    The specific flaw exists within the Lotus Notes file viewer utilizing
    the KeyView SDK to render a malformed Word document. The application
    will copy an arbitrarily sized ASCII string representing the font name
    into a constant sized buffer located on the stack. If large enough this
    will lead to a buffer overflow and can lead to code execution under the
    context of the application.
    
    -- Vendor Response:
    IBM states:
    Autonomy corrected the above issues in the patch releases of versions
    10.10, 10.8, 10.4, 9.2, 7.4 of IDOL Keyview on February 28, 2010.
    
    IBM states:
    http://www-01.ibm.com/support/docview.wss?rs=463&uid=swg21440812
    
    -- Disclosure Timeline:
    2010-01-22 - Vulnerability reported to vendor
    2010-08-23 - Coordinated public release of advisory
    
    -- Credit:
    This vulnerability was discovered by:
        * Anonymous
    
    -- About the Zero Day Initiative (ZDI):
    Established by TippingPoint, The Zero Day Initiative (ZDI) represents 
    a best-of-breed model for rewarding security researchers for responsibly
    disclosing discovered vulnerabilities.
    
    Researchers interested in getting paid for their security research
    through the ZDI can find more information and sign-up at:
    
        http://www.zerodayinitiative.com
    
    The ZDI is unique in how the acquired vulnerability information is
    used. TippingPoint does not re-sell the vulnerability details or any
    exploit code. Instead, upon notifying the affected product vendor,
    TippingPoint provides its customers with zero day protection through
    its intrusion prevention technology. Explicit details regarding the
    specifics of the vulnerability are not exposed to any parties until
    an official vendor patch is publicly available. Furthermore, with the
    altruistic aim of helping to secure a broader user base, TippingPoint
    provides this vulnerability information confidentially to security
    vendors (including competitors) who have a vulnerability protection or
    mitigation product.
    
    Our vulnerability disclosure policy is available online at:
    
        http://www.zerodayinitiative.com/advisories/disclosure_policy/
    
    Follow the ZDI on Twitter:
    
        http://twitter.com/thezdi
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ZDI-10-158: IBM Lotus Notes Autonomy KeyView WK3 Parsing Remote Code Execution Vulnerability
    http://www.zerodayinitiative.com/advisories/ZDI-10-158
    August 23, 2010
    
    -- CVSS:
    10, (AV:N/AC:L/Au:N/C:C/I:C/A:C)
    
    -- Affected Vendors:
    IBM
    Autonomy
    
    -- Affected Products:
    IBM Lotus Notes
    Autonomy KeyView
    
    -- TippingPoint(TM) IPS Customer Protection:
    TippingPoint IPS customers have been protected against this
    vulnerability by Digital Vaccine protection filter ID 10005. 
    For further product information on the TippingPoint IPS, visit:
    
        http://www.tippingpoint.com
    
    -- Vulnerability Details:
    This vulnerability allows remote attackers to execute arbitrary code on
    vulnerable installations of IBM Lotus Notes Email Client. User
    interaction is required to exploit this vulnerability in that the target
    must open a malicious email attachment.
    
    The specific flaw exists within the Lotus Notes file viewer utilizing
    the KeyView SDK to render a malformed .wk3 document. The application
    will mistrust a length used to allocate a buffer. Later, the application
    will use a differently calculated length in a copy used to initialize
    that buffer. This leads to a buffer overflow and can lead to code
    execution under the context of the application.
    
    -- Vendor Response:
    Autonomy states:
    Autonomy corrected the above issues in the patch releases of versions
    10.10, 10.8, 10.4, 9.2, 7.4 of IDOL Keyview on February 28, 2010.
    
    IBM states:
    http://www-01.ibm.com/support/docview.wss?rs=463&uid=swg21440812
    
    -- Disclosure Timeline:
    2010-01-22 - Vulnerability reported to vendor
    2010-08-23 - Coordinated public release of advisory
    
    -- Credit:
    This vulnerability was discovered by:
        * Anonymous
    
    -- About the Zero Day Initiative (ZDI):
    Established by TippingPoint, The Zero Day Initiative (ZDI) represents 
    a best-of-breed model for rewarding security researchers for responsibly
    disclosing discovered vulnerabilities.
    
    Researchers interested in getting paid for their security research
    through the ZDI can find more information and sign-up at:
    
        http://www.zerodayinitiative.com
    
    The ZDI is unique in how the acquired vulnerability information is
    used. TippingPoint does not re-sell the vulnerability details or any
    exploit code. Instead, upon notifying the affected product vendor,
    TippingPoint provides its customers with zero day protection through
    its intrusion prevention technology. Explicit details regarding the
    specifics of the vulnerability are not exposed to any parties until
    an official vendor patch is publicly available. Furthermore, with the
    altruistic aim of helping to secure a broader user base, TippingPoint
    provides this vulnerability information confidentially to security
    vendors (including competitors) who have a vulnerability protection or
    mitigation product.
    
    Our vulnerability disclosure policy is available online at:
    
        http://www.zerodayinitiative.com/advisories/disclosure_policy/
    
    Follow the ZDI on Twitter:
    
        http://twitter.com/thezdi
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ZDI-10-159: IBM Lotus Notes Autonomy KeyView WK3 Parsing Remote Code Execution Vulnerability
    http://www.zerodayinitiative.com/advisories/ZDI-10-159
    August 23, 2010
    
    -- CVSS:
    10, (AV:N/AC:L/Au:N/C:C/I:C/A:C)
    
    -- Affected Vendors:
    IBM
    Autonomy
    
    -- Affected Products:
    IBM Lotus Notes
    Autonomy KeyView
    
    -- TippingPoint(TM) IPS Customer Protection:
    TippingPoint IPS customers have been protected against this
    vulnerability by Digital Vaccine protection filter ID 10246. 
    For further product information on the TippingPoint IPS, visit:
    
        http://www.tippingpoint.com
    
    -- Vulnerability Details:
    This vulnerability allows remote attackers to execute arbitrary code on
    vulnerable installations of IBM Lotus Notes Email Client. User
    interaction is required to exploit this vulnerability in that the target
    must open a malicious email attachment.
    
    The specific flaw exists within the Lotus Notes file viewer utilizing
    the KeyView SDK to render a malformed .wk3 document. The application
    will trust a length specified in the file in order to read a number of
    bytes into a statically allocated buffer. This leads to a buffer
    overflow and can lead to code execution under the context of the
    application.
    
    -- Vendor Response:
    IBM states:
    Autonomy corrected the above issues in the patch releases of versions
    10.10, 10.8, 10.4, 9.2, 7.4 of IDOL Keyview on February 28, 2010.
    
    IBM states:
    http://www-01.ibm.com/support/docview.wss?rs=463&uid=swg21440812
    
    -- Disclosure Timeline:
    2010-01-22 - Vulnerability reported to vendor
    2010-08-23 - Coordinated public release of advisory
    
    -- Credit:
    This vulnerability was discovered by:
        * Anonymous
    
    -- About the Zero Day Initiative (ZDI):
    Established by TippingPoint, The Zero Day Initiative (ZDI) represents 
    a best-of-breed model for rewarding security researchers for responsibly
    disclosing discovered vulnerabilities.
    
    Researchers interested in getting paid for their security research
    through the ZDI can find more information and sign-up at:
    
        http://www.zerodayinitiative.com
    
    The ZDI is unique in how the acquired vulnerability information is
    used. TippingPoint does not re-sell the vulnerability details or any
    exploit code. Instead, upon notifying the affected product vendor,
    TippingPoint provides its customers with zero day protection through
    its intrusion prevention technology. Explicit details regarding the
    specifics of the vulnerability are not exposed to any parties until
    an official vendor patch is publicly available. Furthermore, with the
    altruistic aim of helping to secure a broader user base, TippingPoint
    provides this vulnerability information confidentially to security
    vendors (including competitors) who have a vulnerability protection or
    mitigation product.
    
    Our vulnerability disclosure policy is available online at:
    
        http://www.zerodayinitiative.com/advisories/disclosure_policy/
    
    Follow the ZDI on Twitter:
    
        http://twitter.com/thezdi
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra