CVE-2007-4464 Information

Description

CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via strings with CRLF sequences in the IMAGE_EXPORT_DIRECTORY array in a PE file which could complicate forensics investigations.

Reference

http://blog.hispasec.com/lab/230 http://blog.hispasec.com/lab/advisories/adv_Fileinfo-2_09_multiple_vulnerabilities.txt http://osvdb.org/46834 http://securityreason.com/securityalert/3044 http://www.securityfocus.com/archive/1/477170/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/36127

Share on: