PT-2007-1664 · Ef · Ef Commander

Published

2007-01-11

·

Updated

2017-07-29

·

CVE-2007-0180

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EF Commander version 5.75
Description The issue is a stack-based buffer overflow that allows attackers to execute arbitrary code. This is achieved through a crafted ISO file containing a file within several nested directories, resulting in a large filename that triggers the overflow.
Recommendations For EF Commander version 5.75, update to a newer version that contains a fix for this issue. As a temporary workaround, consider avoiding the use of crafted ISO files that could trigger the buffer overflow.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0180

Affected Products

Ef Commander