Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ICEOWS ICEGUI.DLL ACE File Processing Buffer Overflow Vulnerability

ICEOWS is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer while processing filenames in ACE archives.

Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.

ICEOWS 4.20b is vulnerable; prior versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus