CVE-2007-4725
Last modified
CVE-2007-4725 is a vulnerability of currently unknown severity. Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.. EPSS estimates a 5.56% chance of exploitation in the next 30 days.
Description
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| 7-Zip | 7-Zip | <= 4.42 | — |
| 7-Zip | 7-Zip | 4.43 | Beta |
| 7-Zip | 7-Zip | 4.44 | Beta |
| 7-Zip | 7-Zip | 4.45 | Beta |
| 7-Zip | 7-Zip | 4.46 | Beta |
| 7-Zip | 7-Zip | 4.47 | Beta |
| 7-Zip | 7-Zip | 4.48 | Beta |
| 7-Zip | 7-Zip | 4.49 | Beta |
| 7-Zip | 7-Zip | 4.50 | Beta |
| 7-Zip | 7-Zip | 4.51 | Beta |
| 7-Zip | 7-Zip | 4.52 | Beta |
References
- http://akky.cjb.net/security/7-zip3.txtBroken Link
- http://jvn.jp/jp/JVN%2362868899/index.htmlThird Party Advisory
- http://osvdb.org/40482Broken Link
- http://secunia.com/advisories/26624Third Party Advisory
- http://sourceforge.net/project/shownotes.php?release_id=535160&group_id=14481Product, Third Party Advisory
- http://www.securityfocus.com/bid/25545Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3086Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36459Third Party Advisory, VDB Entry
- http://akky.cjb.net/security/7-zip3.txtBroken Link
- http://jvn.jp/jp/JVN%2362868899/index.htmlThird Party Advisory
- http://osvdb.org/40482Broken Link
- http://secunia.com/advisories/26624Third Party Advisory
- http://sourceforge.net/project/shownotes.php?release_id=535160&group_id=14481Product, Third Party Advisory
- http://www.securityfocus.com/bid/25545Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3086Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36459Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4725?
How severe is CVE-2007-4725?
How do I fix CVE-2007-4725?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4719SQL injection vulnerability in read.php in 212cafeBoard 6.30…
- CVE-2007-4720Unspecified vulnerability in the Shared Trace Service in Hit…
- CVE-2007-4721Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-4722Multiple stack-based buffer overflows in the Quantum Streami…
- CVE-2007-4723Directory traversal vulnerability in Ragnarok Online Control…
- CVE-2007-4724Cross-site request forgery (CSRF) vulnerability in cal2.jsp …
- CVE-2007-4726Directory traversal vulnerability in Web Oddity 0.09b allows…
- CVE-2007-4727Buffer overflow in the fcgi_env_add function in mod_proxy_ba…
- CVE-2007-4730Buffer overflow in the compNewPixmap function in compalloc.c…
- CVE-2007-4731Stack-based buffer overflow in the TMregChange function in T…
- CVE-2007-4732Unspecified vulnerability in the strfreectty function in the…
- CVE-2007-4733The Aztech DSL600EU router, when WAN access to the web inter…
Are you affected by CVE-2007-4725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
