2024-12-08 03:06:42 +00:00

108 lines
3.7 KiB
JSON

{
"id": "CVE-2007-2352",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-04-30T22:19:00.000",
"lastModified": "2024-11-21T00:30:34.573",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp. NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de formato de cadena en AFFLIB 2.2.6 permiten a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante par\u00e1metros de l\u00ednea de comandos concretos, que se usan en llamadas (1) warn y (2) err , posiblemente involucrando (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, y (f) tools/afxml.cpp. \r\nNOTA: Este identificador intenta cubrir los vectores que no fueron corregidos en CVE-2007-2054, pero los vectores no corregidos no fueron listados explicitamente."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 10.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:afflib:afflib:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.2.6",
"matchCriteriaId": "3629ED5D-E2C5-40CA-9D11-6F8270FE1A6B"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/2657",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/467040/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://securityreason.com/securityalert/2657",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/467040/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
}
],
"evaluatorSolution": "The vendor has addressed this issue with the following product update: http://www.afflib.org/downloads/\r\n"
}