Description: A vulnerability has been reported in file, which potentially can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an unspecified integer underflow within the "file_printf" function, which can be exploited to cause a heap-based buffer overflow.
Changelog: 2007-03-22: Added CVE reference and updated credits.
2007-03-27: Added link to US-CERT.
2007-05-24: Updated "Solution" section and "Solution Status" since the previous fix introduced an integer overflow. Information provided by Colin Percival from FreeBSD.
2008-02-29: Updated "Solution" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.