Vulnerabilities > CVE-2007-1943 - Unspecified vulnerability in ACD Systems Acdsee Photo Manager 9.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ACDSee 9.0 Photo Manager Multiple BMP Denial of Service Vulnerabilities. CVE-2007-1943. Dos exploit for windows platform |
id | EDB-ID:29818 |
last seen | 2016-02-03 |
modified | 2007-04-04 |
published | 2007-04-04 |
reporter | Ivan Fratric |
source | https://www.exploit-db.com/download/29818/ |
title | ACDSee 9.0 Photo Manager Multiple BMP Denial of Service Vulnerabilities |
Nessus
NASL family | FreeBSD Local Security Checks |
NASL id | FREEBSD_PKG_632C98BEAAD24AF2849F41A6862AFD6A.NASL |
description | Imager 0.56 and all earlier versions with BMP support have a security issue when reading compressed 8-bit per pixel BMP files where either a compressed run of data or a literal run of data overflows the scan-line. Such an overflow causes a buffer overflow in a malloc() allocated memory buffer, possibly corrupting the memory arena headers. The effect depends on your system memory allocator, with glibc this typically results in an abort, but with other memory allocators it may be possible to cause local code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25130 |
published | 2007-05-02 |
reporter | This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/25130 |
title | FreeBSD : p5-Imager -- possibly exploitable buffer overflow (632c98be-aad2-4af2-849f-41a6862afd6a) |
code |
|
References
- http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html
- http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html
- http://osvdb.org/34663
- http://osvdb.org/34663
- http://secunia.com/advisories/24779
- http://secunia.com/advisories/24779
- http://securityreason.com/securityalert/2558
- http://securityreason.com/securityalert/2558
- http://www.acdsee.com/support/knowledgebase/article?id=2800
- http://www.acdsee.com/support/knowledgebase/article?id=2800
- http://www.securityfocus.com/archive/1/464726/100/0/threaded
- http://www.securityfocus.com/archive/1/464726/100/0/threaded
- http://www.securityfocus.com/bid/23317
- http://www.securityfocus.com/bid/23317
- http://www.vupen.com/english/advisories/2007/1283
- http://www.vupen.com/english/advisories/2007/1283