10
CVSSv2

CVE-2007-5395

Published: 08/11/2007 Updated: 15/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows remote malicious users to execute arbitrary code via a long word, as reachable through the separate_sentence function.

Vulnerable Product Search on Vulmon Subscribe to Product

link_grammar link_grammar 4.1b

abiword abiword_link_grammar 4.2.4

Vendor Advisories

Debian Bug report logs - #450695 CVE-2007-5395 arbitrary code execution via crafted file Package: link-grammar; Maintainer for link-grammar is Debian QA Group <packages@qadebianorg>; Source for link-grammar is src:link-grammar (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Fri, 9 Nov 2007 10 ...
Alin Rad Pop discovered that AbiWord’s Link Grammar parser did not correctly handle overly-long words If a user were tricked into opening a specially crafted document, AbiWord, or other applications using Link Grammar, could be made to crash ...