CVE-2007-6386
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in PccScan.dll before build 1451 in Trend Micro AntiVirus plus AntiSpyware 2008, Internet Security 2008, and Internet Security Pro 2008 allows user-assisted remote attackers to cause a denial of service (SfCtlCom.exe crash), and allows local users to gain privileges, via a malformed .zip archive with a long name, as demonstrated by a .zip file created via format string specifiers in a crafted .uue file.
Desbordamiento de buffer relacionado con la pila en PccScan.dll, en versiones anteriores a la build 1451 de Trend Micro AntiVirus, además de AntiSpyware 2008, Internet Security 2008, e Internet Security Pro 2008. Permite que atacantes remotos con intervención del usuario provoquen una denegación de serivio (por caída de SfCtlCom.exe), y que usuarios locales ganen privilegios, usando un archivo .zip mal formado, con un nombre largo, tal y como se demuestra con un fichero .zip creado a partir de especificadores de cadenas de formato, en un fichero .uue manipulado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-12-14 CVE Reserved
- 2007-12-15 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/39769 | Vdb Entry | |
http://osvdb.org/39770 | Vdb Entry | |
http://secway.org/advisory/AD20071211.txt | X_refsource_misc | |
http://www.securitytracker.com/id?1019079 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/4191 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38982 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://esupport.trendmicro.com/support/viewxml.do?ContentID=1036464 | 2017-08-08 | |
http://secunia.com/advisories/28038 | 2017-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro Search vendor "Trend Micro" | Trend Micro Antivirus Plus Antispyware Search vendor "Trend Micro" for product "Trend Micro Antivirus Plus Antispyware" | 2008 Search vendor "Trend Micro" for product "Trend Micro Antivirus Plus Antispyware" and version "2008" | bld_1450 |
Affected
| ||||||
Trend Micro Search vendor "Trend Micro" | Trend Micro Internet Security Virus Bust Search vendor "Trend Micro" for product "Trend Micro Internet Security Virus Bust" | 2008 Search vendor "Trend Micro" for product "Trend Micro Internet Security Virus Bust" and version "2008" | bld_1451 |
Affected
| ||||||
Trend Micro Search vendor "Trend Micro" | Trend Micro Internet Security Pro Search vendor "Trend Micro" for product "Trend Micro Internet Security Pro" | * | - |
Affected
|