CVE Vulnerabilities

CVE-2007-2452

Published: Jun 04, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

Affected Software

NameVendorStart VersionEnd Version
FindutilsGnu4.0 (including)4.0 (including)
FindutilsGnu4.1 (including)4.1 (including)
FindutilsGnu4.2.28 (including)4.2.28 (including)
FindutilsGnu4.2.29 (including)4.2.29 (including)
FindutilsGnu4.2.30 (including)4.2.30 (including)
FindutilsUbuntudapper*
FindutilsUbuntudevel*
FindutilsUbuntuedgy*
FindutilsUbuntufeisty*
FindutilsUbuntugutsy*
FindutilsUbuntuhardy*
FindutilsUbuntuintrepid*
FindutilsUbuntujaunty*
FindutilsUbuntukarmic*
FindutilsUbuntulucid*
FindutilsUbuntumaverick*
FindutilsUbuntunatty*

References