CVE Vulnerabilities

CVE-2007-2452

Published: Jun 04, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

Affected Software

Name Vendor Start Version End Version
Findutils Gnu 4.0 (including) 4.0 (including)
Findutils Gnu 4.1 (including) 4.1 (including)
Findutils Gnu 4.2.28 (including) 4.2.28 (including)
Findutils Gnu 4.2.29 (including) 4.2.29 (including)
Findutils Gnu 4.2.30 (including) 4.2.30 (including)
Findutils Ubuntu dapper *
Findutils Ubuntu devel *
Findutils Ubuntu edgy *
Findutils Ubuntu feisty *
Findutils Ubuntu gutsy *
Findutils Ubuntu hardy *
Findutils Ubuntu intrepid *
Findutils Ubuntu jaunty *
Findutils Ubuntu karmic *
Findutils Ubuntu lucid *
Findutils Ubuntu maverick *
Findutils Ubuntu natty *

References