cbcvebase.
CVE-2007-2799
published 2007-05-23

CVE-2007-2799: Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers…

medium5.1CVSS 3.1
AVNACHAuNCPIPAP
Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfile< file 4.21-1 (bookworm)file 4.21-1 (bookworm)
filefile
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1
file_projectfile>= 0 < 4.21-14.21-1

CVSS provenance

nvd5.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv9.3CRITICAL