VDB

CVE-2007-2027

CVE-2007-2027 PUBLISHED

Reported by mitre · Published April 13, 2007

Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a, n/a

Timeline

  • Apr 13, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score

References

  • 25550 third-party-advisoryx_refsource_SECUNIA
  • 2007-0017 vendor-advisoryx_refsource_TRUSTIX
  • USN-457-1 vendor-advisoryx_refsource_UBUNTU
  • 25198 third-party-advisoryx_refsource_SECUNIA
  • ADV-2007-1686 vdb-entryx_refsource_VUPEN
  • 35668 vdb-entryx_refsource_OSVDB
  • x_refsource_CONFIRM
  • oval:org.mitre.oval:def:9741 vdb-entrysignaturex_refsource_OVAL
  • 23844 vdb-entryx_refsource_BID
  • 25169 third-party-advisoryx_refsource_SECUNIA
  • x_refsource_CONFIRM
  • 25255 third-party-advisoryx_refsource_SECUNIA
  • GLSA-200706-03 vendor-advisoryx_refsource_GENTOO
Open in Interactive Console →
$ Console Community · 100/wk Open console ›