Title : ArcSoft MMS Composer Multimedia Messaging Service Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3261 CVE ID : CVE-2006-4131 - CVE-2006-4132
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-11
Technical Description
Multiple vulnerabilities have been identified in ArcSoft MMS Composer, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service. These flaws are due to buffer overflow errors in the "Notification.ind", "M-Retrieve.conf", and "SMIL" parsers when processing malformed MMS (Multimedia Messaging Service) messages, which could be exploited by remote attackers to compromise a vulnerable system via a malicious message.