Vulnerabilities > CVE-2012-0192 - Numeric Errors vulnerability in IBM Lotus Symphony
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | LOTUS_SYMPHONY_3_0_1.NASL |
description | The version of IBM Lotus Symphony on the remote host was found to be earlier than 3.0.1. As such, it is reportedly affected by multiple integer overflows in vlcmi.dll. These vulnerabilities can be triggered by a malicious JPEG or PNG image object embedded in a .DOC file, resulting in arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 59109 |
published | 2012-05-16 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/59109 |
title | IBM Lotus Symphony < 3.0.1 Embedded Image File Handling Remote Overflows |
code |
|
References
- http://osvdb.org/78345
- http://secunia.com/advisories/47245
- http://www.securityfocus.com/bid/51591
- http://www-01.ibm.com/support/docview.wss?uid=swg21578684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72424
- http://osvdb.org/78345
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72424
- http://www-01.ibm.com/support/docview.wss?uid=swg21578684
- http://www.securityfocus.com/bid/51591
- http://secunia.com/advisories/47245