cbcvebase.
CVE-2007-1536
published 2007-03-20

CVE-2007-1536: Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that…

PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
12.23%
95.7th percentile
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianfile< file 4.20-1 (bookworm)file 4.20-1 (bookworm)
debianfile< file 4.21-1 (bookworm)file 4.21-1 (bookworm)
filefile<= 4.19
filefile
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.20-14.20-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.20-14.20-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.20-14.20-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.20-14.20-1

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.