PT-2007-5389 · Guidance · Encase
Published
2007-08-08
·
Updated
2018-10-15
·
CVE-2007-4194
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Guidance Software EnCase version 5.0
Description
The issue allows user-assisted remote attackers to cause a denial of service, potentially consuming stack memory, and may have other unspecified impacts. This is achieved via a malformed file and is related to EnCase's file system parsing.
Recommendations
For Guidance Software EnCase version 5.0, consider avoiding the use of malformed files to prevent potential denial of service attacks until a fix is available. As a temporary workaround, restrict the parsing of unknown or untrusted files by EnCase's file system parsing functionality to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Encase