PT-2007-1582 · Conexware · Paiso.Dll+1

Tan Chew Keong

·

Publicado

2007-01-05

·

Atualizado

2018-10-16

·

CVE-2007-0097

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PowerArchiver 2006 version 9.64.02 PAISO.DLL version 1.7.3.0 (1.7.3 beta)
Description The issue is related to multiple stack-based buffer overflows in the LoadTree and ReadHeader functions. This can be exploited by user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.
Recommendations For PowerArchiver 2006 version 9.64.02, consider avoiding the use of PAISO.DLL version 1.7.3.0 (1.7.3 beta) until a patch is available. As a temporary workaround, restrict the handling of crafted ISO files to minimize the risk of exploitation. Avoid using the LoadTree and ReadHeader functions in PAISO.DLL until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0097

Produtos afetados

Paiso.Dll
Powerarchiver