ACDSee Products TIFF and Font Parsing Buffer Overflow Vulnerabilities
2 Jun. 2009
Summary
Two critical vulnerabilities affecting various ACDSee products have been discovered. The first issue is caused by a buffer overflow error when parsing a specially crafted TIFF image, which could be exploited to crash an affected application or execute arbitrary code by tricking a user into opening a malicious image. The second vulnerability is caused by a buffer overflow error when handling malformed Fonts, which could be exploited to crash an affected application or execute arbitrary code by tricking a user into opening a malicious file.