CVE-2007-1007 — Use of Externally-Controlled Format String in Ekiga
7 documents6 sources
Severity
10.0CRITICALNVD
EPSS
12.8%
top 5.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 3
Description
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages2 packages
Also affects: Enterprise Linux 3.0, 4.0