CVE-2007-4036

** DISPUTED ** Guidance Software EnCase allows user-assisted remote attackers to cause a denial of service via (1) a corrupted Microsoft Exchange database, which triggers an application crash when many options are selected; (2) a corrupted NTFS filesystem, which causes the application to report "memory allocation errors;" or (3) deeply nested directories, which trigger an application crash during an Expand All action. NOTE: the vendor disputes the significance of these vectors because the user can select fewer options, there is no operational impact, or the user can do less expansion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:guidance_software:encase:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:34

Type Values Removed Values Added
References () http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Palmer - () http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Palmer -
References () http://www.isecpartners.com/files/iSEC-Breaking_Forensics_Software-Paper.v1_1.BH2007.pdf - () http://www.isecpartners.com/files/iSEC-Breaking_Forensics_Software-Paper.v1_1.BH2007.pdf -
References () http://www.securityfocus.com/archive/1/474727/100/0/threaded - () http://www.securityfocus.com/archive/1/474727/100/0/threaded -
References () http://www.securityfocus.com/archive/1/474750/100/0/threaded - () http://www.securityfocus.com/archive/1/474750/100/0/threaded -
References () http://www.securityfocus.com/archive/1/474809/100/0/threaded - () http://www.securityfocus.com/archive/1/474809/100/0/threaded -
References () http://www.securityfocus.com/archive/1/475335/100/0/threaded - () http://www.securityfocus.com/archive/1/475335/100/0/threaded -
References () http://www.securityfocus.com/bid/25100 - () http://www.securityfocus.com/bid/25100 -

Information

Published : 2007-07-27 22:30

Updated : 2025-04-09 00:30


NVD link : CVE-2007-4036

Mitre link : CVE-2007-4036

CVE.ORG link : CVE-2007-4036


JSON object : View

Products Affected

guidance_software

  • encase
CWE
CWE-399

Resource Management Errors