// For flags

CVE-2007-4197

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 omits NULL pointer checks in certain code paths, which allows user-assisted remote attackers to cause a denial of service (NULL dereference and application crash) and prevent examination of certain NTFS files via a malformed NTFS image.

icat en Brian Carrier The Sleuth Kit (TSK) anterior a 2.09 omite comprobaciones de puntero nulo (NULL) en determinados caminos de ejecución, lo cual permite a atacantes remotos con la intervención del usuario provocar una denegación de servicio (referencia a NULL y caída de la aplicación) y evita el examen de determinados archivos NTFS mediante una imagen NTFS mal formada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-08-07 CVE Reserved
  • 2007-08-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Brian Carrier
Search vendor "Brian Carrier"
The Slueth Kit
Search vendor "Brian Carrier" for product "The Slueth Kit"
<= 2.08
Search vendor "Brian Carrier" for product "The Slueth Kit" and version " <= 2.08"
-
Affected