Computer Security
[EN] no-pyccku

elinks format string vulnerability
SecurityVulns ID:7585
Threat Level:
Description:Relative path is used to search text strings (.po) file. It makes it possible to spoof the file and to conduct format string attack.
Affected:ELINKS : elinks 0.11
CVE:CVE-2007-2027 (Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod