PT-2007-3370 · Elinks+1 · Elinks+1
Arnaud Giersch
+1
·
Publicado
2007-04-13
·
Atualizado
2017-10-11
·
CVE-2007-2027
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Elinks version 0.11.1
Description
The issue is related to an untrusted search path vulnerability in the add filename to string function. This allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory. The vulnerability can be leveraged to conduct format string attacks.
Recommendations
For Elinks version 0.11.1, consider restricting access to the
add filename to string function in intl/gettext/loadmsgcat.c until a patch is available. Avoid using untrusted gettext message catalogs (.po files) in "../po" directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Elinks
Red Hat