Vulnerabilities > CVE-2007-4546 - Unspecified vulnerability in X-Diesel Unreal Commander 0.92Build565/0.92Build573
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a user into performing a dangerous file overwrite or creation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://osvdb.org/45831
- http://osvdb.org/45831
- http://securityreason.com/securityalert/3060
- http://securityreason.com/securityalert/3060
- http://www.securityfocus.com/archive/1/477432/100/0/threaded
- http://www.securityfocus.com/archive/1/477432/100/0/threaded
- http://www.securityfocus.com/bid/25419
- http://www.securityfocus.com/bid/25419