{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[],"affected_systems_content":"<P><TT>file</TT> versions ant\u00e9rieures \u00e0 4.20.</P>","content":"## Description\n\nUne vuln\u00e9rabilit\u00e9 de type d\u00e9bordement d'entier dans la fonction\nfile_printf du programme file permet \u00e0 une personne malintentionn\u00e9e\nd'ex\u00e9cuter du code arbitraire \u00e0 distance avec les droits de\nl'utilisateur.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2007-2799","url":"https://www.cve.org/CVERecord?id=CVE-2007-2799"},{"name":"CVE-2007-1536","url":"https://www.cve.org/CVERecord?id=CVE-2007-1536"}],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 Debian DSA-1274-1 du 02 avril 2007 :","url":"http://www.debian.org/security/2007/dsa-1274"},{"title":"Bulletin de s\u00e9curit\u00e9 Debian DSA-1343-1 du 31 juillet 2007 :","url":"http://www.debian.org/security/2007/dsa-1343"},{"title":"Bulletin de s\u00e9curit\u00e9 Mandriva MDKSA-2007:067 du 22 mars    2007 :","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:067"},{"title":"Bulletin de s\u00e9curit\u00e9 Redhat RHSA-2007-0391-3 du 30 mai 2007    :","url":"http://rhn.redhat.com/errata/RHSA-2007-0391.html"},{"title":"Bulletin de s\u00e9curit\u00e9 FreeBSD-SA-07:04 du 23 mai 2007 :","url":"http://security.freebsd.org/advisories/FreeBSD-SA-07:04.file.asc"},{"title":"Bulletin de s\u00e9curit\u00e9 SuSE SUSE-SR:2007:005 du 30 mars 2007    :","url":"http://www.novell.com/linux/security/advisories/2007_5_sr.html"},{"title":"Bulletin de s\u00e9curit\u00e9 Avaya ASA-2007-179 du 04 mai 2007 :","url":"http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm"},{"title":"Bulletin de s\u00e9curit\u00e9 Gentoo GLSA-200703-26 du 30 mars 2007    :","url":"http://www.gentoo.org/security/en/glsa/glsa-200703-26.xml"},{"title":"Bulletin de s\u00e9curit\u00e9 Redhat RHSA-2007-0124-2 du 23 mars    2007 :","url":"http://rhn.redhat.com/errata/RHSA-2007-0124.html"},{"title":"Bulletin de s\u00e9curit\u00e9 Ubuntu USN-439-1 du 21 mars 2007 :","url":"http://www.ubuntu.com/usn/usn-439-1"},{"title":"Bulletin de s\u00e9curit\u00e9 Gentoo GLSA-200705-25 du 31 mars 2007    :","url":"http://www.gentoo.org/security/en/glsa/glsa-200705-25.xml"},{"title":"Mise \u00e0 jour de s\u00e9curit\u00e9 de file 4.20 du 02 mars 2007 :","url":"http://mx.gw.com/pipermail/file/2007/000161.html"}],"reference":"CERTA-2007-AVI-138","revisions":[{"description":"version initiale.","revision_date":"2007-03-26T00:00:00.000000"},{"description":"ajout des r\u00e9f\u00e9rences Debian, Mandriva, SuSE, Gentoo, Avaya, Redhat, Ubuntu.","revision_date":"2007-05-07T00:00:00.000000"},{"description":"ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 FreeBSD.","revision_date":"2007-05-29T00:00:00.000000"},{"description":"ajout de la r\u00e9f\u00e9rence CVE et des r\u00e9f\u00e9rences aux bulletins de s\u00e9curit\u00e9 Gentoo, RedHat.","revision_date":"2007-06-01T00:00:00.000000"},{"description":"ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 Debian.","revision_date":"2007-08-01T00:00:00.000000"}],"risks":[{"description":"Ex\u00e9cution de code arbitraire \u00e0 distance"}],"summary":null,"title":"Vuln\u00e9rabilit\u00e9 dans file","vendor_advisories":[{"published_at":null,"title":"Mise \u00e0 jour de file","url":null}]}
