|
|
| |
|
| |
chmlib: remote execution of arbitrary code
| Package(s): | chmlib |
CVE #(s): | CVE-2007-0619
|
| Created: | February 27, 2007 |
Updated: | February 28, 2007 |
| Description: |
When certain CHM files that contain tables and objects stored in pages are
parsed by CHMlib, an unsanitized value is passed to the alloca() function
resulting in a shift of the stack pointer to arbitrary memory locations.
An attacker could entice a user to open a specially crafted CHM file,
resulting in the execution of arbitrary code with the permissions of the
user viewing the file. |
| Alerts: |
|
( Log in to post comments)
|
|
|