CVE-2007-4375 Information
Description
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional 2007 Pro Premier and probably other versions exposes a memory comparison function via RPC over TCP which allows remote attackers to (1) obtain sensitive information (process memory contents) as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065245.html http://osvdb.org/39546 http://osvdb.org/39547 http://secunia.com/advisories/26431 http://securityreason.com/securityalert/3018 http://www.securityfocus.com/archive/1/476954/100/0/threaded http://www.securityfocus.com/bid/25320 https://exchange.xforce.ibmcloud.com/vulnerabilities/36007 https://exchange.xforce.ibmcloud.com/vulnerabilities/36008
Share on: