First published: Wed Aug 22 2007(Updated: )
Stack-based buffer overflow in vstlib32.dll 1.2.0.1012 in the SSAPI Engine 5.0.0.1066 through 5.2.0.1012 in Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security 2007 15.0 through 15.3, when the Venus Spy Trap (VST) feature is enabled, allows local users to cause a denial of service (service crash) or execute arbitrary code via a file with a long pathname, which triggers the overflow during a ReadDirectoryChangesW callback notification.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro PC-cillin | =15.3 | |
Trend Micro PC-cillin | =15.0 | |
Trend Micro AntiSpyware | =3.5 | |
Trend Micro PC-cillin | =15.2 | |
Trend Micro PC-cillin | =15.2_patch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3873 is classified as a medium severity vulnerability.
CVE-2007-3873 allows local users to cause a denial of service when the Venus Spy Trap feature is enabled in affected Trend Micro software.
CVE-2007-3873 affects Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security versions 15.0 to 15.3.
To fix CVE-2007-3873, users should update their Trend Micro software to the latest version released by the vendor.
No, CVE-2007-3873 is not remotely exploitable as it requires local user access to trigger the vulnerability.