Vulnerability Name: | CVE-2007-1007 (CCN-32705) | ||||||||||||||||||||
Assigned: | 2007-02-13 | ||||||||||||||||||||
Published: | 2007-02-13 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function. | ||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20070201-01-P Source: CONFIRM Type: UNKNOWN http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266 Source: MITRE Type: CNA CVE-2007-1007 Source: OSVDB Type: UNKNOWN 32083 Source: CCN Type: RHSA-2007-0086 Critical: gnomemeeting security update Source: SECUNIA Type: Patch, Vendor Advisory 24185 Source: SECUNIA Type: UNKNOWN 24271 Source: SECUNIA Type: UNKNOWN 24284 Source: SECUNIA Type: UNKNOWN 24379 Source: SECUNIA Type: UNKNOWN 25119 Source: CCN Type: ASA-2007-068 gnomemeeting security update (RHSA-2007-0086) Source: DEBIAN Type: UNKNOWN DSA-1262 Source: DEBIAN Type: DSA-1262 gnomemeeting -- format string Source: CCN Type: Ekiga Web site Ekiga ~ Free your speech. Source: MANDRIVA Type: UNKNOWN MDKSA-2007:045 Source: SUSE Type: UNKNOWN SUSE-SR:2007:009 Source: CCN Type: OSVDB ID: 32083 GnomeMeeting gnomemeeting_log_insert name Variable Format String Source: REDHAT Type: Patch, Vendor Advisory RHSA-2007:0086 Source: CCN Type: BID-22613 Ekiga GM_Main_Window_Flash_Message Remote Format String Vulnerability Source: CCN Type: USN-426-1 Ekiga vulnerabilities Source: UBUNTU Type: UNKNOWN USN-426-1 Source: XF Type: UNKNOWN ekiga-loginsert-format-string(32705) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11776 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |