CVE-2007-2799: Integer Overflow
Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2799?
CVE-2007-2799 has a moderate severity level due to the potential for arbitrary code execution.
How do I fix CVE-2007-2799?
To fix CVE-2007-2799, update the "file" program to a version greater than 4.20 that addresses the integer overflow vulnerability.
What systems are affected by CVE-2007-2799?
CVE-2007-2799 primarily affects the "file" program version 4.20 on 32-bit systems.
Can CVE-2007-2799 lead to remote attacks?
CVE-2007-2799 requires user assistance for exploitation, typically through opening a maliciously crafted large file.
What software products include the vulnerable version related to CVE-2007-2799?
CVE-2007-2799 impacts software products like The Sleuth Kit that utilize the vulnerable "file" program version 4.20.