CVE-2007-3873: Buffer Overflow
Stack-based buffer overflow in vstlib32.dll 1.2.0.1012 in the SSAPI Engine 5.0.0.1066 through 5.2.0.1012 in Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security 2007 15.0 through 15.3, when the Venus Spy Trap (VST) feature is enabled, allows local users to cause a denial of service (service crash) or execute arbitrary code via a file with a long pathname, which triggers the overflow during a ReadDirectoryChangesW callback notification.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3873?
CVE-2007-3873 is classified as a medium severity vulnerability.
How does CVE-2007-3873 affect users of Trend Micro software?
CVE-2007-3873 allows local users to cause a denial of service when the Venus Spy Trap feature is enabled in affected Trend Micro software.
What versions of Trend Micro products are affected by CVE-2007-3873?
CVE-2007-3873 affects Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security versions 15.0 to 15.3.
How do I fix CVE-2007-3873?
To fix CVE-2007-3873, users should update their Trend Micro software to the latest version released by the vendor.
Is CVE-2007-3873 a remotely exploitable vulnerability?
No, CVE-2007-3873 is not remotely exploitable as it requires local user access to trigger the vulnerability.