CVE-2007-4546
Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a…
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a user into performing a dangerous file overwrite or creation.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- x-diesel/unreal commander
- Source
- cve@mitre.org
References
- http://osvdb.org/45831
- http://securityreason.com/securityalert/3060
- http://www.securityfocus.com/archive/1/477432/100/0/threaded
- http://www.securityfocus.com/bid/25419Exploit
- http://osvdb.org/45831
- http://securityreason.com/securityalert/3060
- http://www.securityfocus.com/archive/1/477432/100/0/threaded
- http://www.securityfocus.com/bid/25419Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.