CVE-2012-0192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
23/01/2012
Last modified:
29/08/2017

Description

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:lotus_symphony:*:*:*:*:*:*:*:* 3.0.0.3 (including)
cpe:2.3:a:ibm:lotus_symphony:1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_symphony:3.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_symphony:3.0.0.2:*:*:*:*:*:*:*