Vulnerabilities > CVE-2007-4463 - PE File Denial of Service vulnerability in Total Commander FileInfo Plugin

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
fransois-gannier
ghisler
exploit available

Summary

The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.

Vulnerable Configurations

Part Description Count
Application
Fransois_Gannier
1
Application
Ghisler
1

Exploit-Db

descriptionTotal Commander FileInfo 2.09 Plugin Multiple PE File Denial of Service Vulnerabilities. CVE-2007-4463. Dos exploit for windows platform
idEDB-ID:30512
last seen2016-02-03
modified2007-07-20
published2007-07-20
reporterGynvael Coldwind
sourcehttps://www.exploit-db.com/download/30512/
titleTotal Commander FileInfo 2.09 Plugin - Multiple PE File Denial of Service Vulnerabilities