CVE-2007-2452

Publication date 4 June 2007

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
findutils 11.04 natty
Fixed 4.2.31-1
10.10 maverick
Fixed 4.2.31-1
10.04 LTS lucid
Fixed 4.2.31-1
9.10 karmic
Fixed 4.2.31-1
9.04 jaunty
Fixed 4.2.31-1
8.10 intrepid
Fixed 4.2.31-1
8.04 LTS hardy
Fixed 4.2.31-1
7.10 gutsy
Fixed 4.2.31-1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


kees

slocate runs instead of the findutils, and this would require an root-user-owned-db attack or similar.