Vulnerability Name:

CVE-2007-2799 (CCN-34731)

Assigned:2007-05-23
Published:2007-05-23
Updated:2018-10-16
Summary:Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement.
Note: this issue is due to an incorrect patch for CVE-2007-1536.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-189
CWE-190
Vulnerability Consequences:Gain Access
References:Source: NETBSD
Type: UNKNOWN
NetBSD-SA2008-001

Source: MITRE
Type: CNA
CVE-2007-2799

Source: CCN
Type: Apple Web site
About Security Update 2008-002

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=307562

Source: APPLE
Type: UNKNOWN
APPLE-SA-2008-03-18

Source: OSVDB
Type: UNKNOWN
38498

Source: CCN
Type: RHSA-2007-0391
Moderate: file security update

Source: SECUNIA
Type: Vendor Advisory
25394

Source: SECUNIA
Type: Vendor Advisory
25544

Source: CCN
Type: SA25578
Amavis file Integer Underflow and Denial of Service

Source: SECUNIA
Type: Vendor Advisory
25578

Source: SECUNIA
Type: Vendor Advisory
25931

Source: CCN
Type: SA26203
Avaya Products file "file_printf()" Integer Underflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
26203

Source: SECUNIA
Type: Vendor Advisory
26294

Source: SECUNIA
Type: Vendor Advisory
26415

Source: CCN
Type: SA29179
NetBSD file "file_printf()" Integer Underflow Vulnerability

Source: SECUNIA
Type: UNKNOWN
29179

Source: CCN
Type: SA29420
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
29420

Source: CCN
Type: SECTRACK ID: 1018140
file Integer Overflow in file_printf() May Let Local Users Execute Arbitrary Code

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/elmodocs2/security/ASA-2007-290.htm

Source: CCN
Type: ASA-2007-290
file security update (RHSA-2007-0391)

Source: CCN
Type: AMaViS Security Announcement ASA-2007-3
file utility integer underflow / possible DoS

Source: CONFIRM
Type: UNKNOWN
http://www.amavis.org/security/asa-2007-3.txt

Source: DEBIAN
Type: UNKNOWN
DSA-1343

Source: DEBIAN
Type: DSA-1343
file -- integer overflow

Source: CCN
Type: GLSA-200705-25
file: Integer overflow

Source: GENTOO
Type: UNKNOWN
GLSA-200705-25

Source: CCN
Type: GLSA-200710-19
The Sleuth Kit: Integer underflow

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:114

Source: SUSE
Type: UNKNOWN
SUSE-SA:2007:040

Source: CCN
Type: OSVDB ID: 38498
GNU file File Handling Local Overflow

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0391

Source: BUGTRAQ
Type: UNKNOWN
20070524 FLEA-2007-0022-1: file

Source: BID
Type: UNKNOWN
24146

Source: CCN
Type: BID-24146
File Multiple Denial of Service Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1018140

Source: TRUSTIX
Type: UNKNOWN
2007-0024

Source: CCN
Type: USN-439-2
file vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-439-2

Source: VUPEN
Type: Vendor Advisory
ADV-2007-2071

Source: VUPEN
Type: Vendor Advisory
ADV-2008-0924

Source: CCN
Type: Bugzilla Bug 241022
CVE-2007-2799 file integer overflow

Source: CONFIRM
Type: Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=241022

Source: XF
Type: UNKNOWN
file-assert-code-execution(34731)

Source: XF
Type: UNKNOWN
file-assert-code-execution(34731)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1311

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:11012

Source: SUSE
Type: SUSE-SA:2007:040
file integer overflow

Vulnerable Configuration:Configuration 1:
  • cpe:/a:file:file:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:sleuth_kit:the_sleuth_kith:*:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20072799
    V
    CVE-2007-2799
    2022-06-30
    oval:org.opensuse.security:def:42302
    P
    Security update for vim (Important)
    2022-06-16
    oval:org.opensuse.security:def:26221
    P
    Security update for python-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:112224
    P
    file-5.40-1.14 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:31374
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:26177
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:33049
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:26163
    P
    Security update for bind (Important)
    2021-11-11
    oval:org.opensuse.security:def:26153
    P
    Security update for git (Low)
    2021-10-20
    oval:org.opensuse.security:def:32201
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:105754
    P
    file-5.40-1.14 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:32182
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:26124
    P
    Security update for openssl-1_1 (Low)
    2021-09-09
    oval:org.opensuse.security:def:31679
    P
    Security update for xen (Important)
    2021-09-06
    oval:org.opensuse.security:def:31677
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:31672
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:31250
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:26100
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:31231
    P
    Security update for the Linux Kernel (Important)
    2021-07-22
    oval:org.opensuse.security:def:42103
    P
    Security update for containerd (Moderate)
    2021-07-20
    oval:org.opensuse.security:def:32116
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:42532
    P
    file-32bit-4.24-43.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36125
    P
    file-32bit-4.24-43.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36400
    P
    file-devel-4.24-43.27.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31618
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:31623
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:31176
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:32077
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:31165
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:31164
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:31603
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:26025
    P
    Security update for openexr (Moderate)
    2021-04-07
    oval:org.opensuse.security:def:31362
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31363
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:33088
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:31729
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:31728
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:32257
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:31323
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26075
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:32138
    P
    Security update for openssh (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:31099
    P
    Security update for clamav (Important)
    2020-12-22
    oval:org.opensuse.security:def:25979
    P
    Security update for xen (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:35696
    P
    file-32bit-4.24-43.19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41952
    P
    file-32bit-4.24-43.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35895
    P
    file-32bit-4.24-43.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35545
    P
    file-32bit-4.24-43.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32820
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:31014
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25532
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31972
    P
    Security update for jakarta-commons-fileupload (Important)
    2020-12-01
    oval:org.opensuse.security:def:26406
    P
    Security update for mbedtls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25878
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32045
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31767
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26696
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25096
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25673
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27088
    P
    automake on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26016
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:25775
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31833
    P
    Security update for bind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25108
    P
    Security update for sssd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25446
    P
    Security update for nfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31580
    P
    Security update for syslog-ng (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26526
    P
    bind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25828
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:32510
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25949
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25300
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31467
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25521
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26628
    P
    perl-HTML-Parser on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26510
    P
    Security update for nextcloud (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25961
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25438
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31830
    P
    Security update for bind (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25730
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:26681
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31591
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25824
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31918
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26894
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25247
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25871
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32306
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27363
    P
    PackageKit-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26291
    P
    Security update for python-reportlab (Important)
    2020-12-01
    oval:org.opensuse.security:def:25926
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31984
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25259
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31474
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26304
    P
    Security update for python-keystoneclient (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32367
    P
    Security update for syslog-ng (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25675
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31809
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32661
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31013
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25451
    P
    Security update for gdb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26392
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:25750
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31958
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26661
    P
    OpenEXR on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31025
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25589
    P
    Security update for zabbix (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32028
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26450
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25959
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25726
    P
    Security update for python36 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31789
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25097
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:26022
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27123
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25445
    P
    Security update for accountsservice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31448
    P
    Security update for postgresql-init (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25814
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:32471
    P
    Security update for xorg-x11-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25172
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31380
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25457
    P
    Security update for aspell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26579
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25872
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:25950
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:25381
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31774
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32859
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25649
    P
    Security update for libcdio (Low)
    2020-12-01
    oval:org.opensuse.security:def:31816
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26667
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26545
    P
    file-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25522
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31879
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26859
    P
    acpid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25787
    P
    Security update for libwmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26725
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31592
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26234
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25877
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31940
    P
    Recommended update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25248
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31382
    P
    Security update for openvpn
    2020-12-01
    oval:org.opensuse.security:def:26251
    P
    Security update for zziplib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32345
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:27398
    P
    file-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25674
    P
    Security update for the Linux Kernel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26375
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25965
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:32622
    P
    LibVNCServer on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25323
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:31531
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26353
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32411
    P
    Security update for wireshark (Low)
    2020-12-01
    oval:org.opensuse.security:def:25686
    P
    Security update for wicked (Important)
    2020-12-01
    oval:org.opensuse.security:def:31901
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26023
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.mitre.oval:def:19976
    P
    DSA-1343-1 file
    2014-06-23
    oval:org.mitre.oval:def:18466
    P
    DSA-1343-2 file
    2014-06-23
    oval:org.mitre.oval:def:22395
    P
    ELSA-2007:0391: file security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:11012
    V
    Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.
    2013-04-29
    oval:org.debian:def:1343
    V
    integer overflow
    2007-07-31
    oval:com.redhat.rhsa:def:20070391
    P
    RHSA-2007:0391: file security update (Moderate)
    2007-05-30
    BACK
    file file 4.2
    sleuth_kit the sleuth kith *