Title : ACDSee Products Multiple Plugin Client-Side Buffer Overflow Issues VUPEN ID : VUPEN/ADV-2007-3695 CVE ID : CVE-2007-4344 - CVE-2007-6007 - CVE-2007-6009
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-02
Technical Description
Multiple vulnerabilities have been identified in various ACDSee products, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer and integer overflow errors in the "ID_PSP.apl" and "AM_LHA.apl" plugins when processing malformed files, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a specially crafted PSP or LHA file.