CVE-2007-2799

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
23/05/2007
Last modified:
09/04/2025

Description

Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:file:file:4.2:*:*:*:*:*:*:*
cpe:2.3:a:sleuth_kit:the_sleuth_kith:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools