PT-2007-5529 · Acdsee · Acdsee Photo Editor+1

Jj Reyes

·

Publicado

2007-11-15

·

Atualizado

2018-10-15

·

CVE-2007-4344

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ACDSee Photo Manager version 9.0 build 108 ACDSee Pro Photo Manager version 8.1 build 99 ACDSee Photo Editor version 4.0 build 195
Description The issue is related to multiple input validation errors, allowing user-assisted remote attackers to execute arbitrary code. This can be achieved via a long section string in either a PSP image to the ID PSP.apl plug-in or an LHA archive to the AM LHA.apl plug-in, resulting in a heap-based buffer overflow.
Recommendations For ACDSee Photo Manager version 9.0 build 108, consider disabling the ID PSP.apl and AM LHA.apl plug-ins until a patch is available. For ACDSee Pro Photo Manager version 8.1 build 99, restrict access to the ID PSP.apl and AM LHA.apl plug-ins to minimize the risk of exploitation. For ACDSee Photo Editor version 4.0 build 195, avoid using the affected plug-ins with untrusted PSP images or LHA archives until the issue is resolved.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4344

Produtos afetados

Acdsee Photo Editor
Acdsee Photo Manager