CVE-2007-1536: Buffer Overflow
Published Mar 20, 2007
·Updated
Integer underflow in the fileprintf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.
Affected Software
1 affected component
file file<=4.19
Remediation
Patch Available
Patch Available
Event History
Mar 20, 2007
CVE Published
08:19 PM
Mar 21, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1536?
CVE-2007-1536 has a high severity due to the potential for remote code execution resulting from a buffer overflow.
2
How do I fix CVE-2007-1536?
To mitigate CVE-2007-1536, upgrade the 'file' program to version 4.20 or later.
3
What systems are affected by CVE-2007-1536?
CVE-2007-1536 affects the 'file' software versions up to and including 4.19.
4
What type of attack is associated with CVE-2007-1536?
CVE-2007-1536 is associated with user-assisted attacks that leverage an integer underflow to execute arbitrary code.
5
Who discovered CVE-2007-1536?
CVE-2007-1536 was discovered and reported by security researchers focusing on vulnerabilities in the 'file' program.