[Bkis-03-2010] Vulnerability in Flash Slideshow Maker Vulnerability
Details: http://security.bkis.com/vulnerability-in-flash-slideshow-maker/
SVRT Advisory: Bkis-03-2010
Initial vendor notification: 05/31/2010
Release Date: 07/01/2010
Update Date: 07/01/2010
Discovered by: Bui Quang Minh - Bkis
Attack Type: Buffer Overflow
Security Rating: High
Impact: Code Execution
Affected Software: Flash Slideshow Maker < v5.00
2.Technical Description
FSS files are used to store essential information about a Flash Slideshow
Maker Project (in XML format). The software performs an inadequate check on
the length of a Photo_Data tag. This results in a critical buffer overflow
error when this tag set with an overly long value.
In order to exploit this vulnerability, a hacker might create a specially
crafted ".fss" file and trick users into using it. If successful, hackers
can perform local attack, inject viruses, steal sensitive information and
even take control of the victim's system.