CVE Database
/

CVE-2007-4375

Back to search

CVE-2007-4375

Published: Aug 16, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.

VendorProductVersions

n/a

n/a

affected
n/a

References

25320
vdb-entry
x_refsource_BID
39546
vdb-entry
x_refsource_OSVDB
39547
vdb-entry
x_refsource_OSVDB
diskeeper-dkservice-dos(36007)
vdb-entry
x_refsource_XF
26431
third-party-advisory
x_refsource_SECUNIA
3018
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now