[inotify-tools] [CVE-2007-5037] buffer overflow, possible execution of arbitrary code, local vulnerability

Bug #180301 reported by disabled.user
258
Affects Status Importance Assigned to Milestone
inotify-tools (Debian)
Fix Released
Unknown
inotify-tools (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: inotify-tools

References:
DSA-1440-1 (http://www.debian.org/security/2007/dsa-1440)

Quoting:
"It was discovered that a buffer overflow in the filename processing of
the inotify-tools, a command-line interface to inotify, may lead to
the execution of arbitrary code. This only affects the internal
library and none of the frontend tools shipped in Debian."

CVE References

Changed in inotify-tools:
status: Unknown → Fix Released
Revision history for this message
Emanuele Gentili (emgent) wrote :

Fixed in hardy.

Revision history for this message
Emanuele Gentili (emgent) wrote :

Fixed in Gutsy too.

Revision history for this message
Emanuele Gentili (emgent) wrote :

Package do not exist in Feisty/edgy/dapper and fixed in hardy/gutsy.

Changed in inotify-tools:
status: New → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.