Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.
| Software | From | Fixed in |
|---|---|---|
| acd_systems / acdsee | 9.0_build_108 | 9.0_build_108.x |
| acd_systems / photo_editor | 4.0_build_195 | 4.0_build_195.x |
| acd_systems / acdsee | 8.1_build_99 | 8.1_build_99.x |