|
Brought to you by:
Suppliers of:
|
|
|
| |
| Two critical vulnerabilities affecting various ACDSee products have been discovered. The first issue is caused by a buffer overflow error when parsing a specially crafted TIFF image, which could be exploited to crash an affected application or execute arbitrary code by tricking a user into opening a malicious image. The second vulnerability is caused by a buffer overflow error when handling malformed Fonts, which could be exploited to crash an affected application or execute arbitrary code by tricking a user into opening a malicious file. |
| |
Credit:
The information has been provided by Nicolas JOLY .
The original article can be found at: http://www.vupen.com/english/advisories/2009/1471
|
| |
Vulnerable Systems:
* ACDSee version 11.x
* ACDSee version 10.x
* ACDSee 9.version x
* ACDSee Photo Manager 2009
* ACDSee Photo Manager 2008
* ACDSee Pro Photo Manager version 2.5
Disclosure Timeline:
2009/04/08 : Vendor contacted
2009/04/15 : Vendor contacted again. No response
2009/04/23 : Vendor contacted again. No response
2009/05/06 : Vendor contacted again. No response
2009/05/25 : Vendor contacted again. No response
2009/06/02 : Public Disclosure
|
|
|
|
|