ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
BID:26554
Info
ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26554 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6009 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2007 12:00AM |
| Updated: | Mar 19 2015 08:49AM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
ACD Systems Inc ACDSee Photo Manager 9.0 ACD Systems Inc ACDSee Photo Manager 8.1 ACD Systems Inc ACDSee Photo Manager 10.0 ACD Systems Inc ACDSee Photo Editor 4.0 |
| Not Vulnerable: | |
Discussion
ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
ACDSee Products are prone to multiple buffer-overflow vulnerabilities because the software fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected software. Failed exploit attempts will result in a denial of service.
These issues affect:
ACDSee Photo Manager 9.0
ACDSee Pro Photo Manager 8.1
ACDSee Photo Editor 4.0
Other versions may also be vulnerable.
Update: Reportedly ACDSee Photo Manager 10.0 is vulnerable to one of these issues.
ACDSee Products are prone to multiple buffer-overflow vulnerabilities because the software fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected software. Failed exploit attempts will result in a denial of service.
These issues affect:
ACDSee Photo Manager 9.0
ACDSee Pro Photo Manager 8.1
ACDSee Photo Editor 4.0
Other versions may also be vulnerable.
Update: Reportedly ACDSee Photo Manager 10.0 is vulnerable to one of these issues.
Exploit / POC
ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits for theses issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for theses issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The vendor has released a fix to address these issues. Please see the references for more information.
ACD Systems Inc ACDSee Photo Editor 4.0
ACD Systems Inc ACDSee Photo Manager 9.0
ACD Systems Inc ACDSee Photo Manager 8.1
Solution:
The vendor has released a fix to address these issues. Please see the references for more information.
ACD Systems Inc ACDSee Photo Editor 4.0
-
ACD Systems Inc idx-2-1-6-en-update.exe
http://files.acdsystems.com/english/p...cdsee/patches/idx-2-1-6-en-upd ate.exe
ACD Systems Inc ACDSee Photo Manager 9.0
-
ACD Systems Inc idx-2-1-6-en-update.exe
http://files.acdsystems.com/english/p...cdsee/patches/idx-2-1-6-en-upd ate.exe
ACD Systems Inc ACDSee Photo Manager 8.1
-
ACD Systems Inc idx-2-1-6-en-update.exe
http://files.acdsystems.com/english/p...cdsee/patches/idx-2-1-6-en-upd ate.exe
References
ACDSee Products Plugins ID_X.APL and IDE_ACDSTD.APL Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- ACDSee Homepage (ACDSee)
- Technical Note: Are there any known security issues using ACD software? (ACD Systems)
- Vulnerability in AcdSee Photo Manager (Trend Micro)