CVE-2007-1007
published 2007-02-20CVE-2007-1007: Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.03%
93.5th percentile
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ekiga | ekiga | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g3j-8rp3-9ggj: Format string vulnerability in GnomeMeeting 1
ghsa_unreviewed·2022-05-03
CVE-2007-1007 [HIGH] GHSA-8g3j-8rp3-9ggj: Format string vulnerability in GnomeMeeting 1
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
Ubuntu
Ekiga vulnerabilities
vendor_ubuntu·2007-02-22
CVE-2007-1006 Ekiga vulnerabilities
Title: Ekiga vulnerabilities
Summary: Ekiga vulnerabilities
Mu Security discovered a format string vulnerability in Ekiga. If a
user was running Ekiga and listening for incoming calls, a remote
attacker could send a crafted call request, and execute arbitrary code
with the user's privileges.
Instructions: After a standard system upgrade you need to restart Ekiga to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2007-02-13·CVSS 10.0
CVE-2007-1007 [CRITICAL] security flaw
security flaw
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
No detection rules found.
Bugzilla
CVE-2007-1007 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2007-1007 [CRITICAL] CVE-2007-1007 security flaw
CVE-2007-1007 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
Bugzilla
CVE-2007-1007 gnomemeeting format string flaw
bugzilla·2007-02-19·CVSS 10.0
CVE-2007-1007 [CRITICAL] CVE-2007-1007 gnomemeeting format string flaw
CVE-2007-1007 gnomemeeting format string flaw
+++ This bug was initially created as a clone of Bug #229259 +++
A format string flaw was found in the way Ekiga processes certain messages form
remote clients. This flaw could allow a remote attacker to execute arbitrary
code as the user running Ekiga. This flaw also affects gnomemeeting
This flaw also affects RHEL3
Discussion:
well a case of replacing gnomemeeting_log_insert (msg); with
gnomemeeting_log_insert ("%s",msg); etc
---
I think it's important to note that the format string flaws in Ekiga are not the
same as the format string flaws in Gnomemeeting, although they are of a similar
root cause.. In Ekiga this occurs because the remote name is passed to a
display function as a format string, in GnomeMeeting because the remote name
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266http://osvdb.org/32083http://secunia.com/advisories/24185http://secunia.com/advisories/24271http://secunia.com/advisories/24284http://secunia.com/advisories/24379http://secunia.com/advisories/25119http://www.debian.org/security/2007/dsa-1262http://www.mandriva.com/security/advisories?name=MDKSA-2007:045http://www.novell.com/linux/security/advisories/2007_9_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0086.htmlhttp://www.ubuntu.com/usn/usn-426-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11776ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266http://osvdb.org/32083http://secunia.com/advisories/24185http://secunia.com/advisories/24271http://secunia.com/advisories/24284http://secunia.com/advisories/24379http://secunia.com/advisories/25119http://www.debian.org/security/2007/dsa-1262http://www.mandriva.com/security/advisories?name=MDKSA-2007:045http://www.novell.com/linux/security/advisories/2007_9_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0086.htmlhttp://www.ubuntu.com/usn/usn-426-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11776
2007-02-20
Published