CVE-2007-4200 describes a denial-of-service vulnerability in Brian Carrier's The Sleuth Kit (TSK) versions prior to 2.09, specifically within the ntfs.c component of fsstat. This flaw arises from an incorrect interpretation of a variable as a byte count instead of a 32-bit integer count when processing malformed NTFS images. An attacker, with user assistance, could exploit this to crash the application, preventing forensic examination of affected NTFS files. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack vector with medium complexity and a partial availability impact. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.08CPE matchmatch criteria | cpe:2.3:a:brian_carrier:the_slueth_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.