CVE Database
/

CVE-2007-6386

Back to search

CVE-2007-6386

Published: Dec 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Stack-based buffer overflow in PccScan.dll before build 1451 in Trend Micro AntiVirus plus AntiSpyware 2008, Internet Security 2008, and Internet Security Pro 2008 allows user-assisted remote attackers to cause a denial of service (SfCtlCom.exe crash), and allows local users to gain privileges, via a malformed .zip archive with a long name, as demonstrated by a .zip file created via format string specifiers in a crafted .uue file.

VendorProductVersions

n/a

n/a

affected
n/a

References

28038
third-party-advisory
x_refsource_SECUNIA
ADV-2007-4191
vdb-entry
x_refsource_VUPEN
trendmicro-pccscan-zip-bo(38982)
vdb-entry
x_refsource_XF
39769
vdb-entry
x_refsource_OSVDB
1019079
vdb-entry
x_refsource_SECTRACK
39770
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now