CVE Vulnerabilities

CVE-2007-2452

Published: Jun 04, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

Affected Software

Name Vendor Start Version End Version
Findutils Gnu 4.0 (including) 4.0 (including)
Findutils Gnu 4.1 (including) 4.1 (including)
Findutils Gnu 4.2.28 (including) 4.2.28 (including)
Findutils Gnu 4.2.29 (including) 4.2.29 (including)
Findutils Gnu 4.2.30 (including) 4.2.30 (including)

References