Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-2027
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2027

Description:
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-457-1

TRUSTIX
  http://www.trustix.org/errata/2007/0017/

SAID
  Secunia Advisory: SA25169
  Secunia Advisory: SA25198
  Secunia Advisory: SA25255
  Secunia Advisory: SA25550

OSVDB
  35668

GENTOO
  http://security.gentoo.org/glsa/glsa-200706-03.xml

CONFIRM
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417789

BID
  23844


Return to the previous page.