CVE-2007-2027: Medium severity ELinks Elinks vulnerability
Published Apr 13, 2007
·Updated
Untrusted search path vulnerability in the addfilenametostring function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.
Affected Software
1 affected component
ELinks Elinks=0.11.1
Event History
Apr 13, 2007
CVE Published
06:19 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2027?
CVE-2007-2027 is considered a moderate severity vulnerability that can lead to format string attacks.
2
How do I fix CVE-2007-2027?
To fix CVE-2007-2027, upgrade to a patched version of Elinks that addresses this vulnerability.
3
Who is affected by CVE-2007-2027?
CVE-2007-2027 affects users of Elinks version 0.11.1.
4
What kind of attacks can CVE-2007-2027 facilitate?
CVE-2007-2027 can be exploited to conduct format string attacks through untrusted gettext message catalogs.
5
Is CVE-2007-2027 exploitable by local users?
Yes, CVE-2007-2027 can be exploited by local users who can manipulate the message catalog files.