CVE-2011-1213
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
- Affected products
- Autonomy Keyview, Ibm Lotus Notes
- Ibm Lotus Notes
- ≤ 8.5.2.2, 3.0, 3.0.0.1, 3.0.0.2, 4.2, 4.2.1, 4.2.2, 4.5, 4.6, 4.6.7a, 4.6.7h, 5.0, 5.0.1, 5.0.1.02, 5.0.1a, 5.0.1b, 5.0.1c, 5.0.2, 5.0.2a, 5.0.2b, 5.0.2c, 5.0.3, 5.0.4, 5.0.4a, 5.0.5, 5.0.5.01, 5.0.5.02, 5.0.6, 5.0.6a, 5.0.6a.01, 5.0.7, 5.0.7a, 5.0.8, 5.0.9, 5.0.9a, 5.0.10, 5.0.11, 5.0.12, 5.0a, 5.02
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 33.0% (98th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2011-05-31
CVE-2011-1213 at NVD
10 known exploits for CVE-2011-1213
Proof-of-concept code and exploit modules indexed by Sploitus
IBM Lotus Notes LZH Attachment Viewer Stack Buffer Overflow
IBM Lotus Notes LZH Attachment Viewer Stack Buffer Overflow
IBM Lotus Notes LZH Attachment Viewer Stack Buffer Overflow
IBM Lotus Notes LZH Attachment Viewer Stack Buffer Overflow
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh attachment)
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh attachment)
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)