CVE-2007-2877: Buffer Overflow
Published May 29, 2007
·Updated
Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths.
Affected Software
1 affected component
Tcl Tk Tcl Tk<=8.5a5
Remediation
Patch Available
Event History
May 29, 2007
CVE Published
08:30 PM
May 30, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2877?
CVE-2007-2877 is considered a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2007-2877?
To fix CVE-2007-2877, upgrade Tcl/Tk to version 8.5a6 or later, which addresses the buffer overflow issue.
3
Who is affected by CVE-2007-2877?
Local users of Tcl/Tk versions prior to 8.5a6 are affected by CVE-2007-2877.
4
What type of vulnerability is CVE-2007-2877?
CVE-2007-2877 is a buffer overflow vulnerability that affects the registry key handling in Tcl/Tk.
5
Can CVE-2007-2877 be exploited remotely?
CVE-2007-2877 cannot be exploited remotely as it requires local user access to the affected software.