PT-2007-5104 · Trend Micro · Ssapi Engine+3

Publicado

2007-08-22

·

Atualizado

2017-07-29

·

CVE-2007-3873

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Trend Micro AntiSpyware version 3.5 PC-Cillin Internet Security versions 15.0 through 15.3 SSAPI Engine versions 5.0.0.1066 through 5.2.0.1012 vstlib32.dll version 1.2.0.1012
Description: The issue is a stack-based buffer overflow that occurs in the vstlib32.dll when the Venus Spy Trap (VST) feature is enabled. This happens when a file with a long pathname triggers the overflow during a ReadDirectoryChangesW callback notification, potentially allowing local users to cause a denial of service or execute arbitrary code.
Recommendations: For Trend Micro AntiSpyware version 3.5, disable the Venus Spy Trap (VST) feature to prevent exploitation. For PC-Cillin Internet Security versions 15.0 through 15.3, restrict access to the VST feature until a patch is available. For SSAPI Engine versions 5.0.0.1066 through 5.2.0.1012, consider disabling the ReadDirectoryChangesW callback notification as a temporary workaround. For vstlib32.dll version 1.2.0.1012, avoid using long pathnames in files to minimize the risk of triggering the buffer overflow.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3873

Produtos afetados

Pc-Cillin Internet Security
Ssapi Engine
Trend Micro Antispyware
Vstlib32.Dll