VDB
CVE-2007-2027
CVE-2007-2027
PUBLISHED
Reported by mitre · Published April 13, 2007
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Apr 13, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 25550 third-party-advisoryx_refsource_SECUNIA
- 2007-0017 vendor-advisoryx_refsource_TRUSTIX
- USN-457-1 vendor-advisoryx_refsource_UBUNTU
- 25198 third-party-advisoryx_refsource_SECUNIA
- ADV-2007-1686 vdb-entryx_refsource_VUPEN
- 35668 vdb-entryx_refsource_OSVDB
- x_refsource_CONFIRM
- oval:org.mitre.oval:def:9741 vdb-entrysignaturex_refsource_OVAL
- 23844 vdb-entryx_refsource_BID
- 25169 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- 25255 third-party-advisoryx_refsource_SECUNIA
- GLSA-200706-03 vendor-advisoryx_refsource_GENTOO