Описание
Integer overflow in the ID_PSP.apl plug-in for ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted PSP image that triggers a heap-based buffer overflow.
Ссылки
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:acdsee:photo_editor:4.0:build_195:*:*:*:*:*:*
cpe:2.3:a:acdsee:photo_manager:9.0:build_108:*:*:*:*:*:*
cpe:2.3:a:acdsee:pro_photo_manager:8.1:build_99:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04663
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-119
Связанные уязвимости
github
почти 4 года назад
Integer overflow in the ID_PSP.apl plug-in for ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted PSP image that triggers a heap-based buffer overflow.
EPSS
Процентиль: 89%
0.04663
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-119