CVE-2007-2054
Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp. NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- afflib/afflib
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/2657
- http://www.securityfocus.com/archive/1/467040/100/0/threaded
- http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txtPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33969
- http://securityreason.com/securityalert/2657
- http://www.securityfocus.com/archive/1/467040/100/0/threaded
- http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txtPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33969
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.