|
Multiple SpeedProject Products ACE Archive Filename Handling Buffer Overflow Vulnerability
Multiple SpeedProject products are prone to a buffer-overflow vulnerability. This issue is due to the applications' failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. Attackers can exploit this vulnerability to execute arbitrary code in the context of the user who extracts a malicious archive. Squeez version 5.10 Build 4460 and SpeedCommander versions 10.52 Build 4450 and 11.01 Build 4450 are affected by this issue; prior versions may also be affected. |
|
|
Privacy Statement |