Wordperfect Files Cause Buffer Overflow


Recommended Posts

18 March 2009, 17:28

WordPerfect files cause buffer overflow

The WordPerfect office suite the former Microsoft Office competitor, now a quiet sideline product at Corel, has caused a stir: a library for processing and displaying WordPerfect files contains a critical buffer overflow that can be exploited to inject and execute arbitrary code.

The SDK Autonomy KeyView library is used by a number of products such as IBM's Lotus Notes and various Symantec email scanners. Ironically, it is also used by several products that are designed for data loss prevention. Attackers can use specially crafted emails with malformed attachments to trigger the overflow and inject programs like spyware and malware applications.

In Notes, users still have to manually open this attachment, but Symantec's Mail Security solutions open them automatically. Interestingly, Symantec says that the risk is reduced in Symantec Mail Security for SMTP, because the scan module runs at a lower privilege level. However, similar security measures of this kind do not seem to exist in the respective products for Exchange and Domino.

This is not the first time that Autonomy KeyView libraries have caused security troubles. A year ago, Secunia discovered several holes which also affected Symantec Mail Security and Lotus Notes. iDefense already informed the vendors at the end of 2008 and suitable updates or patches have been released.

See also:

(crve)

Heise security - http://www.h-online.com/security/WordPerfe...w--/news/112881

>>>>>>>>>>>>>>>>>>>>

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...