Unrated severityNVD Advisory· Published Apr 30, 2007· Updated Apr 23, 2026
CVE-2007-2053
CVE-2007-2053
Description
Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path. NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.securityfocus.com/bid/23695nvdPatch
- www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txtnvdPatchVendor Advisory
- osvdb.org/35613nvd
- osvdb.org/35614nvd
- osvdb.org/35615nvd
- securityreason.com/securityalert/2655nvd
- www.securityfocus.com/archive/1/467038/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33961nvd
News mentions
0No linked articles in our index yet.