CVE-2010-1525Integer Underflow (Wrap or Wraparound) in Keyview Export SDK

CWE-1893 documents3 sources
Severity
9.3CRITICALNVD
EPSS
2.6%
top 14.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 17

Description

Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDautonomy/keyview_export_sdk10.4, 10.9+1
NVDautonomy/keyview_filter_sdk10.4, 10.9+1
NVDautonomy/keyview_viewer_sdk10.4, 10.9+1

🔴Vulnerability Details

2
GHSA
GHSA-5f3f-jp3c-jp83: Integer underflow in the SpreadSheet Lotus 123 reader (wkssr2022-05-17
CVEList
CVE-2010-1525: Integer underflow in the SpreadSheet Lotus 123 reader (wkssr2010-08-17
CVE-2010-1525 — Integer Underflow (Wrap or Wraparound) | cvebase