9.3

CVE-2007-4344

Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an LHA archive to the AM_LHA.apl plug-in, resulting in a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AcdseePhoto Editor Version4.0 Updatebuild_195
AcdseePhoto Manager Version9.0 Updatebuild_108
AcdseePro Photo Manager Version8.1 Updatebuild_99
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.76% 0.907
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.acdsee.com/support/knowledgebase/article?id=2800
http://secunia.com/advisories/25952
Patch
Vendor Advisory
http://secunia.com/secunia_research/2007-73/advisory/
http://securityreason.com/securityalert/3367
http://www.securityfocus.com/archive/1/483188/100/0/threaded
http://www.securityfocus.com/bid/26297
Patch
http://www.vupen.com/english/advisories/2007/3695