CVE-2007-2683
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.8%
from disclosure to weapon13 days
Published on NVDMay 15
1st PoC+13d
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30093⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://dev.mutt.org/trac/ticket/2885http://osvdb.org/34973https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=239890http://secunia.com/advisories/25408http://secunia.com/advisories/25515http://secunia.com/advisories/25529http://secunia.com/advisories/25546http://secunia.com/advisories/26415https://exchange.xforce.ibmcloud.com/vulnerabilities/34441https://issues.rpath.com/browse/RPL-1391https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10543http://www.mandriva.com/security/advisories?name=MDKSA-2007:113