CVE-2007-6531: Buffer Overflow
Published Jan 9, 2008
·Updated
Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via Launcher tooltips. NOTE: a second buffer overflow (over-read) in the xfcemkdirhier function was also reported, but it might not be exploitable for a crash or code execution, so it is not a vulnerability.
Affected Software
1 affected component
Xfce xfce<=4.4.1
Event History
Jan 9, 2008
CVE Published
11:46 PM
Jan 10, 2008
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6531?
CVE-2007-6531 is classified with a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2007-6531?
To address CVE-2007-6531, upgrade Xfce to version 4.4.2 or later.
3
What causes the vulnerability CVE-2007-6531?
CVE-2007-6531 is caused by a stack-based buffer overflow in the xfce4-panel component.
4
Which versions of Xfce are affected by CVE-2007-6531?
Xfce versions before 4.4.2 are affected by CVE-2007-6531.
5
Can CVE-2007-6531 be exploited remotely?
Yes, CVE-2007-6531 can be exploited remotely via malicious Launcher tooltips.