vendor:
Salamander
by:
patrick
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Salamander
Affected Version From: Altap Salamander <= v2.5
Affected Version To: Altap Salamander <= v2.5
Patch Exists: NO
Related CWE: CVE-2007-3314
CPE: a:altap:salamander:2.5
Platforms Tested: Windows
2007
Altap Salamander 2.5 PE Viewer Buffer Overflow
This module exploits a buffer overflow in Altap Salamander <= v2.5. By creating a malicious file and convincing a user to view the file with the Portable Executable Viewer plugin within a vulnerable version of Salamander, the PDB file string is copied onto the stack and the SEH can be overwritten.
Mitigation:
Update to a patched version of Altap Salamander.