HIGH · 9.3

CVE-2007-6020

Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activeP...

Vulnerability Description

Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ActivepdfDocconverter3.8.4.0
AutonomyKeyview2.0.0.2
IbmLotus Notes6.0
SymantecMail Security5.0
SymantecMail Security Appliance5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-6020?

CVE-2007-6020 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activeP...

How severe is CVE-2007-6020?

CVE-2007-6020 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6020?

Check the references section above for vendor advisories and patch information. Affected products include: Activepdf Docconverter, Autonomy Keyview, Ibm Lotus Notes, Symantec Mail Security, Symantec Mail Security Appliance.