FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-19 18:22:07 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
7ca2a709-103b-11dc-8e82-00001cd613f9findutils -- GNU locate heap buffer overrun

James Youngman reports:

When GNU locate reads filenames from an old-format locate database, they are read into a fixed-length buffer allocated on the heap. Filenames longer than the 1026-byte buffer can cause a buffer overrun. The overrunning data can be chosen by any person able to control the names of filenames created on the local system. This will normally include all local users, but in many cases also remote users (for example in the case of FTP servers allowing uploads).


Discovery 2007-05-30
Entry 2007-06-01
findutils
< 4.2.31

CVE-2007-2452
http://lists.gnu.org/archive/html/bug-findutils/2007-06/msg00000.html