Overview
Guidance Software's EnCase Forensic can only detect the first 25 partitions on a volume.
Description
Guidance Software's EnCase Forensic is a tool that allows an investigator to acquire and analyze a disk image. EnCase names partitions either c: through z:, with an additional partition named \[. EnCase Forensic may only detect the first 25 partitions on a volume. The hidden partitions are searchable, but not can not be browsed. |
Impact
An attacker may be able to hide or obscure data. |
Solution
Guidance Encase customers should see the Guidance support portal for information about obtaining fixed software. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www.guidancesoftware.com/products/ef_index.aspx
- http://www.isecpartners.com/files/iSEC-Breaking_Forensics_Software-Paper.v1_1.BH2007.pdf
- http://www.securityfocus.com/archive/1/474727
- http://www.securityfocus.com/archive/1/archive/1/474727/100/0/threaded
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4201
Acknowledgements
This report was based on information released by iSec partners.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-4201 |
Severity Metric: | 0.85 |
Date Public: | 2007-08-03 |
Date First Published: | 2007-11-09 |
Date Last Updated: | 2007-11-20 18:36 UTC |
Document Revision: | 20 |