First published: Mon Jun 04 2007(Updated: )
Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU findutils | =4.2.28 | |
GNU findutils | =4.2.29 | |
GNU findutils | =4.2.30 | |
GNU findutils | =4.1 | |
GNU findutils | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2452 has a high severity rating due to the potential for arbitrary code execution.
To fix CVE-2007-2452, update GNU findutils to version 4.2.31 or later.
CVE-2007-2452 affects GNU findutils versions 4.0 to 4.2.30.
CVE-2007-2452 is classified as a heap-based buffer overflow vulnerability.
CVE-2007-2452 can be exploited by context-dependent attackers using specially crafted long pathnames.