Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Arnaud Giersch

#53244of 56,330
4.4Total CVSS
Vulnerabilities · 1
PT-2007-3370
4.4
2007-04-13
Elinks · Elinks · CVE-2007-2027
**Name of the Vulnerable Software and Affected Versions** Elinks version 0.11.1 **Description** The issue is related to an untrusted search path vulnerability in the add filename to string function. This allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory. The vulnerability can be leveraged to conduct format string attacks. **Recommendations** For Elinks version 0.11.1, consider restricting access to the `add filename to string` function in `intl/gettext/loadmsgcat.c` until a patch is available. Avoid using untrusted gettext message catalogs (.po files) in "../po" directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.