CVE-2007-2452

NameCVE-2007-2452
SourceCVE (at NVD; RH)
DescriptionHeap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
NVD severitymedium (attack range: remote, user-initiated)
Debian Bugs426862
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
findutils (PTS)lenny4.4.0-2fixed
squeeze4.4.2-1fixed
wheezy, sid4.4.2-4fixed
experimental4.5.10-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
findutilssource(unstable)4.2.31-1low426862
findutilssourceetch4.2.28-1etch1low

Notes

[sarge] - findutils <no-dsa> (Not vulnerable in default configuration, minor issue)

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint