Vulnerability Description
Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a certain large offset. NOTE: the vendor disputes the significance of this issue, asserting that relevant attackers typically do not corrupt a filesystem, and indicating that the relevant read operation can be disabled
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Guidance Software | Encase | All versions |
Related Weaknesses (CWE)
References
- http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Palmer
- http://www.isecpartners.com/files/iSEC-Breaking_Forensics_Software-Paper.v1_1.BH
- http://www.securityfocus.com/archive/1/474727/100/0/threaded
- http://www.securityfocus.com/archive/1/474750/100/0/threaded
- http://www.securityfocus.com/archive/1/474809/100/0/threaded
- http://www.securityfocus.com/archive/1/475335/100/0/threaded
- http://www.securityfocus.com/bid/25100
- http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Palmer
- http://www.isecpartners.com/files/iSEC-Breaking_Forensics_Software-Paper.v1_1.BH
- http://www.securityfocus.com/archive/1/474727/100/0/threaded
- http://www.securityfocus.com/archive/1/474750/100/0/threaded
- http://www.securityfocus.com/archive/1/474809/100/0/threaded
- http://www.securityfocus.com/archive/1/475335/100/0/threaded
- http://www.securityfocus.com/bid/25100
FAQ
What is CVE-2007-4037?
CVE-2007-4037 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a certain large offse...
How severe is CVE-2007-4037?
CVE-2007-4037 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4037?
Check the references section above for vendor advisories and patch information. Affected products include: Guidance Software Encase.