Vulnerability Name: | CVE-2007-2683 (CCN-34441) | ||||||||||||||||
Assigned: | 2007-05-11 | ||||||||||||||||
Published: | 2007-05-11 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion. | ||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:L/AC:H/Au:S/C:P/I:P/A:P) 2.5 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:UR)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:UR)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-2683 Source: MISC Type: UNKNOWN http://dev.mutt.org/trac/ticket/2885 Source: OSVDB Type: UNKNOWN 34973 Source: CCN Type: RHSA-2007-0386 Moderate: mutt security update Source: CCN Type: SA25408 Mutt GECOS Name Processing Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 25408 Source: SECUNIA Type: UNKNOWN 25515 Source: SECUNIA Type: UNKNOWN 25529 Source: SECUNIA Type: UNKNOWN 25546 Source: SECUNIA Type: UNKNOWN 26415 Source: CCN Type: SECTRACK ID: 1018066 Mutt mutt_gecos_name() Buffer Overflow May Let Local Users Gain Elevated Privileges Source: CCN Type: ASA-2007-296 Mutt security update (RHSA-2007-0386) Source: MANDRIVA Type: UNKNOWN MDKSA-2007:113 Source: CCN Type: Mutt Web site The Mutt E-Mail Client Source: CCN Type: OSVDB ID: 34973 Mutt GECOS Field Alias Expansion Overflow Source: REDHAT Type: UNKNOWN RHSA-2007:0386 Source: BID Type: UNKNOWN 24192 Source: CCN Type: BID-24192 Mutt Mutt_Gecos_Name Function Local Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1018066 Source: TRUSTIX Type: UNKNOWN 2007-0024 Source: CCN Type: Red Hat Bugzilla Bug 239890 Buffer overflow in mutt's gecos structure handling Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=239890 Source: XF Type: UNKNOWN mutt-gecos-bo(34441) Source: XF Type: UNKNOWN mutt-gecos-bo(34441) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-1391 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10543 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |