Photo DVD Maker Professional Buffer Overflow Vulnerability
6 Jul. 2009
Summary
There is a vulnerability in the software related to the processing of Photo DVD Maker Professional project files (".pdm"). This vulnerability permits hackers to execute malicious code on users systems.
Vulnerable Systems:
* Photo DVD Maker Professional version 8.02 and prior
PDM files are used to store essential information about a Photo DVD Maker Professional Project (in XML format). The software performs inadequate check for the length of a File_Name tag. This results in a critical buffer overflow error when set with an overly long value.
To exploit this vulnerability, a hacker might create a specially crafted ".pdm" file and trick users into using it. If successful, hackers can perform local attack, inject viruses, steal sensitive information and even take control of the victim's system.
Disclosure Timeline:
12/06/2009 Initial vendor notification
06/07/2009 Release Date