CVE-2009-1515

Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.

Date published : 2009-05-04

http://www.securityfocus.com/bid/34745

ftp://ftp.astron.com/pub/file/file-5.01.tar.gz