PT-2007-5643 · Total Commander · Fileinfo Plugin

Published

2007-08-21

·

Updated

2018-10-15

·

CVE-2007-4463

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Fileinfo plugin for Total Commander version 2.0.9
Description The issue allows user-assisted remote attackers to cause a denial of service via an invalid RVA address function pointer in a PE file, specifically involving the OriginalFirstThunk and FirstThunk fields in an IMAGE IMPORT DESCRIPTOR, or the AddressOfNames field in an IMAGE EXPORT DIRECTORY.
Recommendations For Fileinfo plugin for Total Commander version 2.0.9, update to a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4463

Affected Products

Fileinfo Plugin