This application requires Javascript for optimal performance.

ACDSee.FotoSlate.PLP.File.Overflow

Release Date

Nov 03, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Double Free vulnerability in ACDSee FotoSlate.

The vulnerability is caused by an error that occurs when the software handles a malicious "PLP" file. A remote attacker may exploit this to execute arbitrary code via a crafted "PLP" file.

Affected Products

ACDSee FotoSlate version 4.0 Build 146

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-2595

Reference/s

http://www.securityfocus.com/bid/49558 (BugTraq)

Reference: VID-29624