CVE-2007-4037

** DISPUTED **

Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a certain large offset. NOTE: the vendor disputes the significance of this issue, asserting that relevant attackers typically do not corrupt a filesystem, and indicating that the relevant read operation can be disabled.

Date published : 2007-07-27

http://www.securityfocus.com/bid/25100

http://www.securityfocus.com/archive/1/474727/100/0/threaded