CVE-2007-2053

N/A Unknown
Published: April 30, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path. NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/35613
Source: cve@mitre.org
http://osvdb.org/35614
Source: cve@mitre.org
http://osvdb.org/35615
Source: cve@mitre.org
http://www.securityfocus.com/bid/23695
Source: cve@mitre.org
Patch
http://osvdb.org/35613
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35614
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35615
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/2655
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/467038/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/23695
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txt
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/33961
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
20.5%
96th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

afflib