Vulnerabilities > CVE-2007-3314 - Buffer Overflow vulnerability in Altap Servant Salamander PE File Handling

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
altap
exploit available
metasploit

Summary

Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.

Exploit-Db

descriptionAltap Salamander 2.5 PE Viewer Buffer Overflow. CVE-2007-3314. Local exploit for windows platform
idEDB-ID:16656
last seen2016-02-02
modified2010-12-16
published2010-12-16
reportermetasploit
sourcehttps://www.exploit-db.com/download/16656/
titleAltap Salamander 2.5 PE Viewer Buffer Overflow

Metasploit

descriptionThis module exploits a buffer overflow in Altap Salamander <= v2.5. By creating a malicious file and convincing a user to view the file with the Portable Executable Viewer plugin within a vulnerable version of Salamander, the PDB file string is copied onto the stack and the SEH can be overwritten.
idMSF:EXPLOIT/WINDOWS/FILEFORMAT/ALTAP_SALAMANDER_PDB
last seen2020-03-23
modified2020-01-15
published2009-08-30
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/fileformat/altap_salamander_pdb.rb
titleAltap Salamander 2.5 PE Viewer Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83171/altap_salamander_pdb.rb.txt
idPACKETSTORM:83171
last seen2016-12-05
published2009-11-26
reporterpatrick
sourcehttps://packetstormsecurity.com/files/83171/Altap-Salamander-2.5-PE-Viewer-Buffer-Overflow.html
titleAltap Salamander 2.5 PE Viewer Buffer Overflow

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:71164
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-71164
titleAltap Salamander 2.5 PE Viewer Buffer Overflow