CVE-2007-4547
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users.
Unreal Commander 0.92 construcción 565 y 573 escribe porciones de la pila de memoria dentro de los archivos locales cuando estraen de un archivo con información de tamaño malformado en un archivo de cabecera, lo cual permite a atacantes con la intervención de un usuario obtener información sensible (contenido de memoria) a través de la lectura de los archivos extraidos. NOTA: este asunto es solo una vulnerabilidad si Unteal está funcionando con privilegios, o si los archivos extraidos se han hecho accesibles a otros usuarios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-08-27 CVE Reserved
- 2007-08-27 CVE Published
- 2024-06-30 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/45832 | Vdb Entry | |
http://securityreason.com/securityalert/3060 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/477432/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/25419 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
X-diesel Search vendor "X-diesel" | Unreal Commander Search vendor "X-diesel" for product "Unreal Commander" | 0.92_build565 Search vendor "X-diesel" for product "Unreal Commander" and version "0.92_build565" | - |
Affected
| ||||||
X-diesel Search vendor "X-diesel" | Unreal Commander Search vendor "X-diesel" for product "Unreal Commander" | 0.92_build573 Search vendor "X-diesel" for product "Unreal Commander" and version "0.92_build573" | - |
Affected
|