Stack overflow libgtop when pathname of mmap()-ed file is too long
Published Jan 16, 2007
3.7
LOWCVSS 2.0
EPSS 0.89%
Description
Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libgtop as shipped with Red Hat Enterprise Linux 2.1 or 3. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. This flaw affects Red Hat Enterprise Linux 4 and is being tracked via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=249884
References (28)
- http://bugzilla.gnome.org/show_bug.cgi?id=396477 x_refsource_CONFIRM
- http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news x_refsource_CONFIRM
- http://osvdb.org/32815 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/23736 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23777 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23814 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23840 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23872 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24015 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/26367 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200701-17.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2007/dsa-1255 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:023 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2007-0765.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/22054 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018526 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-407-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/0185 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0187 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-0235 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=222637 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-0237 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31522 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-972 x_refsource_CONFIRM
- https://launchpad.net/bugs/79206 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2007-0235
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10720 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-0235
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data