CVE-2007-4725
AkkyWareHOUSE '7-zip32.dll' 4.42 - Heap Buffer Overflow
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.
Vulnerabilidad de consumo de pila en AkkyWareHOUSE 7-zip32.dll anterior a 4.42.00.04, como el derivado de Igor Pavlov 7-Zip anterior a 4.53 beta, permite a atacantes remotos con la complicidad del usuario ejecutar código de su elección mediante un nombre de fichero largo en un archivo, que acaba en un desbordamiento de búfer basado en pila.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-09-04 First Exploit
- 2007-09-05 CVE Reserved
- 2007-09-05 CVE Published
- 2024-07-09 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://akky.cjb.net/security/7-zip3.txt | Broken Link | |
http://jvn.jp/jp/JVN%2362868899/index.html | Third Party Advisory | |
http://osvdb.org/40482 | Broken Link | |
http://secunia.com/advisories/26624 | Third Party Advisory | |
http://sourceforge.net/project/shownotes.php?release_id=535160&group_id=14481 | Product | |
http://www.securityfocus.com/bid/25545 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2007/3086 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36459 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30565 | 2007-09-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | <= 4.42 Search vendor "7-zip" for product "7-zip" and version " <= 4.42" | - |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.43 Search vendor "7-zip" for product "7-zip" and version "4.43" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.44 Search vendor "7-zip" for product "7-zip" and version "4.44" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.45 Search vendor "7-zip" for product "7-zip" and version "4.45" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.46 Search vendor "7-zip" for product "7-zip" and version "4.46" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.47 Search vendor "7-zip" for product "7-zip" and version "4.47" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.48 Search vendor "7-zip" for product "7-zip" and version "4.48" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.49 Search vendor "7-zip" for product "7-zip" and version "4.49" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.50 Search vendor "7-zip" for product "7-zip" and version "4.50" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.51 Search vendor "7-zip" for product "7-zip" and version "4.51" | beta |
Affected
| ||||||
7-zip Search vendor "7-zip" | 7-zip Search vendor "7-zip" for product "7-zip" | 4.52 Search vendor "7-zip" for product "7-zip" and version "4.52" | beta |
Affected
|