cbcvebase.
CVE-2007-2799
published 2007-05-23

CVE-2007-2799: Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers…

PriorityP423medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.70%
84.3th percentile
Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfile< file 4.21-1 (bookworm)file 4.21-1 (bookworm)
filefile
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.