Vulnerability Note VU#849841
Autonomy Keyview IDOL contains multiple vulnerabilities in file parsers
Overview
Autonomy Keyview IDOL contains multiple vulnerabilities in file parsers. These vulnerabilities could allow a remote attacker to execute arbitrary code on an affected system.
Description
Autonomy Keyview IDOL is a set of libraries that can decode over 1,000 different file formats. The Autonomy Keyview IDOL libraries are used by a variety of applications, including IBM Lotus Notes, Lotus Domino, Symantec Mail Security, RSA DLP, VMware Zimbra, Hyland OnBase, and many others. These vulnerabilities result from a number of underlying issues. Some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code. |
Impact
By causing an application to process a specially-crafted file with the Autonomy Keyview IDOL library, a remote, unauthenticated attacker may be able to cause an affected application to crash, resulting in a denial of service, or executing arbitrary code with the privileges of the vulnerable application. Depending on what application is using Keyview IDOL, these may happen as the result of some user interaction, such as single-clicking on a file, or it may happen with no user interaction at all. Privileges that the code would execute with depend on the application in question. For example, an attacker that exploits Symantec Mail Security or IBM Lotus Domino would be able to achieve code execution with SYSTEM privileges. |
Solution
Apply an update This issue is addressed in Autonomy Keyview IDOL 10.16. Please see your vendor for relevant product updates that include this version of Keyview. |
Use the Microsoft Enhanced Mitigation Experience Toolkit |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Autonomy | Affected | - | 04 Jun 2012 |
| CA Technologies | Affected | 29 Mar 2012 | 05 Nov 2012 |
| Cisco Systems, Inc. | Affected | 29 Mar 2012 | 05 Nov 2012 |
| EMC Corporation | Affected | 29 Mar 2012 | 05 Nov 2012 |
| Hewlett-Packard Company | Affected | 05 Mar 2012 | 05 Nov 2012 |
| Hyland Software | Affected | 29 Mar 2012 | 04 Jun 2012 |
| IBM Corporation | Affected | 21 Nov 2012 | 24 Mar 2013 |
| Lotus Software | Affected | 29 Mar 2012 | 24 Mar 2013 |
| McAfee | Affected | 29 Mar 2012 | 05 Nov 2012 |
| Nuance Communications, Inc. | Affected | - | 28 Nov 2012 |
| Oracle Corporation | Affected | - | 28 Nov 2012 |
| Palisade Systems | Affected | 22 May 2012 | 22 May 2012 |
| Proofpoint | Affected | 22 May 2012 | 05 Nov 2012 |
| Symantec | Affected | 29 Mar 2012 | 20 Nov 2012 |
| Trend Micro | Affected | 22 May 2012 | 05 Nov 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 10.0 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Temporal | 8.7 | E:ND/RL:OF/RC:C |
| Environmental | 8.7 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www.autonomy.com/content/Products/idol-modules-connectors/index.en.html
- http://www.autonomy.com/content/Technology/idol-functionality-information-connectivity/index.en.html
- https://customers.autonomy.com
- http://support.microsoft.com/kb/2458544
- http://www.youtube.com/watch?v=28_LUs_g0u4
- http://blogs.technet.com/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx
- http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx
- http://blogs.technet.com/b/srd/archive/2010/12/08/on-the-effectiveness-of-dep-and-aslr.aspx
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20121120_00
- http://www.securityfocus.com/bid/56610
- http://securitytracker.com/id/1027799
- http://www.osvdb.org/show/osvdb/87619
- http://secunia.com/advisories/51362
Credit
This vulnerability was reported by Will Dormann of the CERT/CC.
This document was written by Will Dormann.
Other Information
- CVE IDs: CVE-2012-6277
- Date Public: 20 Nov 2012
- Date First Published: 20 Nov 2012
- Date Last Updated: 24 Mar 2013
- Document Revision: 39
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.