CVE-2007-3314

Altap Salamander 2.5 PE Viewer Buffer Overflow

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-3314. PoCs published by Metasploit, aushack, including Metasploit module exploits/windows/fileformat/altap_salamander_pdb.

AI-analyzed exploit summary This exploit targets a buffer overflow in Altap Salamander <= v2.5 via a malicious PDB file. It overwrites the SEH to achieve remote code execution when the file is viewed in the Portable Executable Viewer plugin.

Description

Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16656

This exploit targets a buffer overflow in Altap Salamander <= v2.5 via a malicious PDB file. It overwrites the SEH to achieve remote code execution when the file is viewed in the Portable Executable Viewer plugin.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Altap Salamander <= 2.5
No auth needed
Prerequisites: User interaction to open the malicious PDB file in Altap Salamander
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by aushack · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/altap_salamander_pdb.rb

This Metasploit module exploits a buffer overflow in Altap Salamander <= v2.5 via a malicious PDB file, overwriting the SEH to achieve arbitrary code execution when viewed with the PE Viewer plugin.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Altap Salamander <= 2.5
No auth needed
Prerequisites: User interaction to open the malicious PDB file in Altap Salamander
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34938
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25732
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37579
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24557
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2268
Exploit x_refsource_misc
http://vuln.sg/salamander25-en.html

Scores

EPSS 0.4341
EPSS Percentile 98.6%

Details

Status published
Products (4)
altap/portable_executable_viewer 2.02
altap/portable_executable_viewer 1.00
altap/servant_salamander 2.5
altap/servant_salamander 2.0
Published Jun 21, 2007
Tracked Since Feb 18, 2026