CVE-2007-4344

Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an LHA archive to the AM_LHA.apl plug-in, resulting in a heap-based buffer overflow.
Configurations

Configuration 1

cpe:2.3:a:acdsee:photo_manager:9.0:build_108:*:*:*:*:*:*
cpe:2.3:a:acdsee:photo_editor:4.0:build_195:*:*:*:*:*:*
cpe:2.3:a:acdsee:pro_photo_manager:8.1:build_99:*:*:*:*:*:*

Information

Published : 2007-11-15 10:46

Updated : 2018-10-15 09:34


NVD link : CVE-2007-4344

Mitre link : CVE-2007-4344

Products Affected
No products.
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-20