CVE-2007-1007Use of Externally-Controlled Format String in Ekiga

7 documents6 sources
Severity
10.0CRITICALNVD
EPSS
12.8%
top 5.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 3

Description

Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Also affects: Enterprise Linux 3.0, 4.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-8g3j-8rp3-9ggj: Format string vulnerability in GnomeMeeting 12022-05-03

💥Exploits & PoCs

1
Exploit-DB
Agnitum Outpost Firewall 4.0 - Outpost_IPC_HDR Local Denial of Service2007-06-04

📋Vendor Advisories

2
Ubuntu
Ekiga vulnerabilities2007-02-22
Red Hat
security flaw2007-02-13

💬Community

2
Bugzilla
CVE-2007-1007 security flaw2018-08-16
Bugzilla
CVE-2007-1007 gnomemeeting format string flaw2007-02-19