Vulnerability Description
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Notes | 8.5 |
| Symantec | Brightmail Gateway | 8.0 |
| Symantec | Data Loss Prevention Detection Servers | 8.1.1 |
| Symantec | Data Loss Prevention Endpoint Agents | 8.1.1 |
| Symantec | Im Manager 2007 | All versions |
| Symantec | Mail Security | 5.0.0 |
Related Weaknesses (CWE)
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=858Exploit
- http://www-01.ibm.com/support/docview.wss?uid=swg21440812
- http://www.securityfocus.com/bid/38468
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securit
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=858Exploit
- http://www-01.ibm.com/support/docview.wss?uid=swg21440812
- http://www.securityfocus.com/bid/38468
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=securit
FAQ
What is CVE-2009-3032?
CVE-2009-3032 is a vulnerability with a CVSS score of 10.0 (HIGH). Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and ot...
How severe is CVE-2009-3032?
CVE-2009-3032 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3032?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Notes, Symantec Brightmail Gateway, Symantec Data Loss Prevention Detection Servers, Symantec Data Loss Prevention Endpoint Agents, Symantec Im Manager 2007.