Heap-Based Buffer Overflow in Autonomy KeyView EML Reader Affecting IBM Lotus Notes
CVE-2007-5399

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
10 April 2008

Summary

The Autonomy KeyView EML Reader, utilized by IBM Lotus Notes, is susceptible to multiple heap-based buffer overflow vulnerabilities. These issues arise from insufficient validation of long header fields including To, Cc, Bcc, From, Date, Subject, among others. An attacker can exploit these vulnerabilities by crafting emails with excessively long input in the specified fields, leading to potential remote code execution. This highlights the importance of strict input validation and handling mechanisms in email processing applications to mitigate risks associated with arbitrary code execution.

References

EPSS Score

39% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.