Vulnerability Name:

CVE-2012-6277 (CCN-80207)

Assigned:2012-11-20
Published:2012-11-20
Updated:2020-03-04
Summary:Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-6277

Source: CCN
Type: SA51362
Autonomy KeyView File Processing Vulnerabilities

Source: CCN
Type: SA51365
Symantec Products KeyView File Processing Vulnerabilities

Source: CCN
Type: SA52599
IBM Lotus Notes Multiple Vulnerabilities

Source: CCN
Type: SA52753
IBM Lotus Domino Multiple Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 1627597
Security vulnerabilities addressed in IBM Domino & IBM Domino Designer 9.0 (CVE-2013-0487, CVE-2012-2161, CVE-2012-2159, CVE-2013-0486, CVE-2012-6277, CVE-2013-0488, CVE-2013-0489)

Source: CCN
Type: Autonomy Web site
KeyView IDOL & Connectors

Source: CCN
Type: IBM Security Bulletin 1627992
Security vulnerabilities addressed in IBM Notes 9.0 (CVE-2011-3026, CVE-2012-6349, CVE-2012-6277)

Source: CCN
Type: US-CERT VU#849841
Autonomy Keyview IDOL contains multiple vulnerabilities in file parsers

Source: CCN
Type: OSVDB ID: 87619
Autonomy KeyView Unspecified File Handling Memory Corruption

Source: CCN
Type: BID-56610
Autonomy Keyview IDOL Multiple Remote Code Execution Vulnerabilities

Source: CCN
Type: SYM12-018
Symantec Updates HP Autonomy Keyview Filter Issues Affecting Multiple Vendors

Source: XF
Type: UNKNOWN
keyview-multiple-code-execution(80207)

Source: MISC
Type: Vendor Advisory
https://support.symantec.com/us/en/article.symsa1262.html

Source: MISC
Type: Third Party Advisory
https://tools.cisco.com/security/center/viewAlert.x?alertId=27482

Source: MISC
Type: Third Party Advisory
https://vulmon.com/vulnerabilitydetails?qid=CVE-2012-6277

Source: MISC
Type: Third Party Advisory, US Government Resource
https://www.energy.gov/cio/articles/v-118-ibm-lotus-domino-multiple-vulnerabilities

Source: MISC
Type: Vendor Advisory
https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-addressed-in-ibm-notes-9-0-cve-2011-3026-cve-2012-6349-cve-2012-6277/

Source: MISC
Type: Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/849841/

Source: MISC
Type: Third Party Advisory, VDB Entry
https://www.securityfocus.com/bid/56610

Source: MISC
Type: Third Party Advisory
https://www.tenable.com/plugins/nessus/67192

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:domino:*:*:*:*:*:*:*:* (Version >= 8.5.0 and <= 8.5.3.6)
  • OR cpe:/a:ibm:lotus_notes:*:*:*:*:*:*:*:* (Version >= 8.5 and <= 8.5.3)

  • Configuration 2:
  • cpe:/a:symantec:data_loss_prevention_endpoint:*:*:*:*:*:*:*:* (Version >= 11.0 and < 11.6.1)
  • OR cpe:/a:symantec:data_loss_prevention_enforce/detection_servers:*:*:*:*:*:linux:*:* (Version >= 11.0 and < 11.6.1)
  • OR cpe:/a:symantec:data_loss_prevention_enforce/detection_servers:*:*:*:*:*:windows:*:* (Version >= 11.0 and < 11.6.1)
  • OR cpe:/a:symantec:mail_security:6.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:mail_security:*:*:*:*:*:microsoft_exchange:*:* (Version <= 6.5.7)
  • OR cpe:/a:symantec:mail_security:*:*:*:*:*:domino:*:* (Version <= 8.1.0)
  • OR cpe:/a:symantec:messaging_gateway:*:*:*:*:*:*:*:* (Version >= 9.5 and < 10.0.1)

  • Configuration 3:
  • cpe:/a:hp:autonomy_keyview_idol:*:*:*:*:*:*:*:* (Version < 10.16)

  • Configuration CCN 1:
  • cpe:/a:autonomy:keyview_viewer_sdk:10:*:*:*:*:*:*:*
  • OR cpe:/a:autonomy:keyview_filter_sdk:10:*:*:*:*:*:*:*
  • OR cpe:/a:autonomy:keyview_export_sdk:10:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_notes:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_notes:8.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_domino:8.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_domino:8.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_domino:8.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_notes:8.5.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:lotus_notes:8.5.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm domino *
    ibm notes *
    symantec data loss prevention endpoint *
    symantec data loss prevention enforce/detection servers *
    symantec data loss prevention enforce/detection servers *
    symantec mail security 6.5.7
    symantec mail security *
    symantec mail security *
    symantec messaging gateway *
    hp autonomy keyview idol *
    autonomy keyview viewer sdk 10
    autonomy keyview filter sdk 10
    autonomy keyview export sdk 10
    ibm lotus notes 8.0
    ibm lotus notes 8.5
    ibm lotus notes 8.5.1
    ibm lotus domino 8.5.1
    ibm lotus domino 8.5.2
    ibm lotus domino 8.5.3
    ibm lotus notes 8.5.2.0
    ibm lotus notes 8.5.3