VDB
CVE-2007-5395
CVE-2007-5395
PUBLISHED
CVSS 10 CRITICAL
Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows remote attackers to execute arbitrary code via a long word, as reachable through the separate_sentence function.
EPSS 9.44% · 93.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
9.44%
93.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| link_grammar | link_grammar | 4.1b |
| abiword | abiword_link_grammar | 4.2.4 |
Timeline
- Nov 8, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 27340 third-party-advisory
- 26365 vdb
- http://secunia.com/secunia_research/2007-78/advisory/ url
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=450695 url
- FEDORA-2007-3339 vendor-advisory
- abiword-linkgrammar-sentence-bo(38317) vdb
- ADV-2007-3771 vdb
- 28101 third-party-advisory
- GLSA-200711-27 vendor-advisory
- ADV-2007-3770 vdb
- DSA-1432 vendor-advisory
- http://bugs.gentoo.org/show_bug.cgi?id=196803 url
- USN-545-1 vendor-advisory
- 27300 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=371221 url
- 20071107 Secunia Research: AbiWord Link Grammar "separate_sentence()"Buffer Overflow mailing-list
- 27702 third-party-advisory
- 27783 third-party-advisory
- 20071107 Secunia Research: Link Grammar "separate_sentence()" BufferOverflow mailing-list
- http://secunia.com/secunia_research/2007-79/advisory/ url
…and 4 more