>> ER Mapper Image Web Server ECW JPEG 2000 Plug-in Code Execution Issues
Title : ER Mapper Image Web Server ECW JPEG 2000 Plug-in Code Execution Issues VUPEN ID : VUPEN/ADV-2007-3093 CVE ID : CVE-2007-4470
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-09-07
Technical Description
Multiple vulnerabilities have been identified in ER Mapper Image Web Server ECW JPEG 2000 Plug-in, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by buffer overflow errors in the NCSView ActiveX control (NCSView.dll) when processing malformed data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.