9.3
CVSSv2

CVE-2007-0999

Published: 10/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote malicious users to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome ekiga

Vendor Advisories

Debian Bug report logs - #414069 CVE-2007-0999: still vulnerable to format string exploits Package: ekiga; Maintainer for ekiga is Kilian Krause <kilian@debianorg>; Source for ekiga is src:ekiga (PTS, buildd, popcon) Reported by: Kees Cook <kees@outfluxnet> Date: Fri, 9 Mar 2007 01:33:01 UTC Severity: grave Tags: ...
It was discovered that Ekiga had format string vulnerabilities beyond those fixed in USN-426-1 If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user’s privileges ...