PT-2007-1664 · Ef · Ef Commander
Published
2007-01-11
·
Updated
2017-07-29
·
CVE-2007-0180
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EF Commander version 5.75
Description
The issue is a stack-based buffer overflow that allows attackers to execute arbitrary code. This is achieved through a crafted ISO file containing a file within several nested directories, resulting in a large filename that triggers the overflow.
Recommendations
For EF Commander version 5.75, update to a newer version that contains a fix for this issue. As a temporary workaround, consider avoiding the use of crafted ISO files that could trigger the buffer overflow.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ef Commander