Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp. NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed.
References
Configurations
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/2657 - | |
References | () http://www.securityfocus.com/archive/1/467040/100/0/threaded - | |
References | () http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt - Patch |
Information
Published : 2007-04-30 22:19
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2352
Mitre link : CVE-2007-2352
CVE.ORG link : CVE-2007-2352
JSON object : View
Products Affected
afflib
- afflib
CWE