CVE-2007-4344

Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an LHA archive to the AM_LHA.apl plug-in, resulting in a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:acdsee:photo_editor:4.0:build_195:*:*:*:*:*:*
cpe:2.3:a:acdsee:photo_manager:9.0:build_108:*:*:*:*:*:*
cpe:2.3:a:acdsee:pro_photo_manager:8.1:build_99:*:*:*:*:*:*

History

No history.

Information

Published : 2007-11-15 22:46

Updated : 2024-02-04 17:13


NVD link : CVE-2007-4344

Mitre link : CVE-2007-4344

CVE.ORG link : CVE-2007-4344


JSON object : View

Products Affected

acdsee

  • pro_photo_manager
  • photo_editor
  • photo_manager
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-20

Improper Input Validation