ACDSee.TIFF.Buffer.Overflow

Last Updated DateJul 02, 2009
Release DateJun 25, 2009
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a buffer-overflow vulnerability in ACDSee.

The vulnerability is caused by an error when the vulnerable software handles a malicious .tiff file. It allows a remote attacker to execute arbitrary code via sending a crafted .tiff file.
Affected ProductsACDSee 9.x
ACDSee Photo Manager 10.x
ACDSee Photo Manager 2009 11.x
ACDSee Pro 2 Photo Manager 2.x
Recommended ActionsDo not open untrusted .tiff files.
Reference/shttp://www.securityfocus.com/bid/35175 (BugTraq)
Reference: VID-17485