Release date:
Updated on:
Affected Systems:
IBM Lotus Symphony 3.0.0 FP 3 Rev. 20110
Unaffected system:
IBM Lotus Symphony 3.0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51591
CVE (CAN) ID: CVE-2012-0192
IBM Lotus Symphony is a free office software released by IBM.
Vclmi in the visual class library module of earlier versions of IBM Lotus Symphony 3.0.1. the dll has multiple integer overflow vulnerabilities. You can use JPEG or PNG images in the Symphony document to allow remote attackers to trigger heap buffer overflow and execute arbitrary code.
<* Source: Tielei Wang (wangtielei@icst.pku.edu.cn)
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg21578684
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/