Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Multiple SpeedProject Products ACE Archive Filename Handling Buffer Overflow Vulnerability

Multiple SpeedProject products are prone to a buffer-overflow vulnerability. This issue is due to the applications' failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Attackers can exploit this vulnerability to execute arbitrary code in the context of the user who extracts a malicious archive.

Squeez version 5.10 Build 4460 and SpeedCommander versions 10.52 Build 4450 and 11.01 Build 4450 are affected by this issue; prior versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus