HIGH · 9.3

CVE-2005-2619

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (...

Vulnerability Description

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AutonomyKeyview Export SdkAll versions
AutonomyKeyview Filter SdkAll versions
AutonomyKeyview Viewer SdkAll versions
IbmLotus Notes6.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-2619?

CVE-2005-2619 is a vulnerability with a CVSS score of 9.3 (HIGH). Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (...

How severe is CVE-2005-2619?

CVE-2005-2619 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2619?

Check the references section above for vendor advisories and patch information. Affected products include: Autonomy Keyview Export Sdk, Autonomy Keyview Filter Sdk, Autonomy Keyview Viewer Sdk, Ibm Lotus Notes.