CVE-2007-2056
Last modified
CVE-2007-2056 is a vulnerability of currently unknown severity. Rejected reason: The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable..
Description
Rejected reason: The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.
Timeline
- Published
- Last Modified
- Status
- Rejected
Frequently Asked Questions
What is CVE-2007-2056?
How severe is CVE-2007-2056?
How do I fix CVE-2007-2056?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2050Multiple directory traversal vulnerabilities in header.php i…
- CVE-2007-2051Buffer overflow in the parsecmd function in bftpd before 1.8…
- CVE-2007-2052Off-by-one error in the PyLocale_strxfrm function in Modules…
- CVE-2007-2053Multiple stack-based buffer overflows in AFFLIB before 2.2.6…
- CVE-2007-2054Multiple format string vulnerabilities in AFFLIB before 2.2.…
- CVE-2007-2055AFFLIB 2.2.8 and earlier allows attackers to execute arbitra…
- CVE-2007-2057Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 a…
- CVE-2007-2058Directory traversal vulnerability in Acubix PicoZip 4.02 all…
- CVE-2007-2059Multiple buffer overflows in the ESA protocol implementation…
- CVE-2007-2060Cross-zone scripting vulnerability in the Wizz RSS Reader be…
- CVE-2007-2061Cross-site scripting (XSS) vulnerability in check_login.asp …
- CVE-2007-2062Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA al…
Are you affected by CVE-2007-2056?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
