CVE-2007-4463
Total Commander FileInfo 2.09 Plugin - Multiple PE File Denial of Service Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.
La extensión Fileinfo 2.0.9 para Total Commander permite a atacantes remotos con la intervención del usuario provocar una denegación de servicio (excepción no capturada) mediante un puntero inválido a la función de dirección RVA en (1) una estructura IMAGE_THUNK_DATA, involucrando los campos (a) OriginalFirstThunk y (b) FirstThunk de IMAGE_IMPORT_DESCRIPTOR, o (2) el campo AddressOfNames de IMAGE_EXPORT_DIRECTORY en un archivo PE.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-20 First Exploit
- 2007-08-21 CVE Reserved
- 2007-08-21 CVE Published
- 2024-08-07 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://blog.hispasec.com/lab/230 | X_refsource_misc | |
http://blog.hispasec.com/lab/advisories/adv_Fileinfo-2_09_multiple_vulnerabilities.txt | X_refsource_misc | |
http://osvdb.org/46835 | Vdb Entry | |
http://securityreason.com/securityalert/3044 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/477170/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36126 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30512 | 2007-07-20 | |
http://www.securityfocus.com/bid/25373 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fransois Gannier Search vendor "Fransois Gannier" | Fileinfo Plugin Search vendor "Fransois Gannier" for product "Fileinfo Plugin" | 2.09 Search vendor "Fransois Gannier" for product "Fileinfo Plugin" and version "2.09" | - |
Affected
| ||||||
Ghisler Search vendor "Ghisler" | Total Commander Search vendor "Ghisler" for product "Total Commander" | * | - |
Affected
|