CVE-2007-4549 Information

Description

Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long file-key or (2) a \Site Information and Folder entry\ with a ciphertext_length value much larger than the plaintext_length value.

Reference

http://secunia.com/advisories/26616 http://vuln.sg/alpass27-en.html http://www.securityfocus.com/bid/25435 https://exchange.xforce.ibmcloud.com/vulnerabilities/36235 https://exchange.xforce.ibmcloud.com/vulnerabilities/36257

Share on: