CVE-2007-6613
libcdio 0.7x - GNU Compact Disc Input and Control Library Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a long joilet file name.
Desbordamiento de búfer basado en pila en la función print_iso9660_recurse de iso-info (src/iso-info.c) en GNU Compact Disc Input and Control Library (libcdio) 0.79 y anteriores permite a atacantes locales o remotos (dependiendo del contexto) provocar una denegación de servicio (core dump) y posiblemente ejecutar código de su elección mediante un disco o imagen que contiene un nombre de archivo joilet largo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-12-30 First Exploit
- 2008-01-03 CVE Reserved
- 2008-01-03 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://lists.gnu.org/archive/html/libcdio-devel/2007-12/msg00009.html | Mailing List | |
http://secunia.com/advisories/28308 | Third Party Advisory | |
http://secunia.com/advisories/28569 | Third Party Advisory | |
http://secunia.com/advisories/28796 | Third Party Advisory | |
http://secunia.com/advisories/28970 | Third Party Advisory | |
http://secunia.com/advisories/29242 | Third Party Advisory | |
http://www.securityfocus.com/bid/27131 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0030 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39405 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30985 | 2007-12-30 | |
http://bugs.gentoo.org/show_bug.cgi?id=203777 | 2024-08-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=427197 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html | 2017-08-08 | |
http://security.gentoo.org/glsa/glsa-200801-08.xml | 2017-08-08 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:037 | 2017-08-08 | |
http://www.ubuntu.com/usn/usn-580-1 | 2017-08-08 |