« List of all CVEs

CVE-2007-2452

Published: 6/4/2007 Last updated: 8/7/2024 Reserved: 5/2/2007

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

conf-findutils

Products affected (1)

Product Vendor Version
n/a n/a 20.11.1.1

References (24)