VulnerabilityModified
CVE-2007-1536
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.
HIGH 9.3EPSS 12.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 12.23% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- file/file
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc
- http://docs.info.apple.com/article.html?artnum=305530
- http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
- http://mx.gw.com/pipermail/file/2007/000161.htmlPatch
- http://openbsd.org/errata40.html#015_file
- http://secunia.com/advisories/24548Patch, Vendor Advisory
- http://secunia.com/advisories/24592Vendor Advisory
- http://secunia.com/advisories/24604Vendor Advisory
- http://secunia.com/advisories/24608Vendor Advisory
- http://secunia.com/advisories/24616Vendor Advisory
- http://secunia.com/advisories/24617Vendor Advisory
- http://secunia.com/advisories/24723Vendor Advisory
- http://secunia.com/advisories/24754Vendor Advisory
- http://secunia.com/advisories/25133Vendor Advisory
- http://secunia.com/advisories/25393Vendor Advisory
- http://secunia.com/advisories/25402Vendor Advisory
- http://secunia.com/advisories/25931Vendor Advisory
- http://secunia.com/advisories/25989Vendor Advisory
- http://secunia.com/advisories/27307Vendor Advisory
- http://secunia.com/advisories/27314Vendor Advisory
- http://secunia.com/advisories/29179Vendor Advisory
- http://security.freebsd.org/advisories/FreeBSD-SA-07:04.file.asc
- http://security.gentoo.org/glsa/glsa-200703-26.xml
- http://security.gentoo.org/glsa/glsa-200710-19.xml
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.512926
- http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm
- http://www.debian.org/security/2007/dsa-1274
- http://www.kb.cert.org/vuls/id/606700US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:067
- http://www.novell.com/linux/security/advisories/2007_40_file.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.