← Vulnerability feed

Vulnerability record · CVE-2007-1536 · published 20 March 2007

CVE-2007-1536: File vulnerability

File · File

Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.

9.3 CVSS 2.0 High EPSS 13% · top 3.7% CWE-189 · CWE-189
9.3CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
86References
16 Jun 2026Last modified by NVD

Description

Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc
http://docs.info.apple.com/article.html?artnum=305530
http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
http://mx.gw.com/pipermail/file/2007/000161.html Patch
http://openbsd.org/errata40.html#015_file
http://secunia.com/advisories/24548 PatchVendor Advisory
http://secunia.com/advisories/24592 Vendor Advisory
http://secunia.com/advisories/24604 Vendor Advisory
http://secunia.com/advisories/24608 Vendor Advisory
http://secunia.com/advisories/24616 Vendor Advisory
http://secunia.com/advisories/24617 Vendor Advisory
http://secunia.com/advisories/24723 Vendor Advisory
http://secunia.com/advisories/24754 Vendor Advisory
http://secunia.com/advisories/25133 Vendor Advisory
http://secunia.com/advisories/25393 Vendor Advisory
http://secunia.com/advisories/25402 Vendor Advisory
http://secunia.com/advisories/25931 Vendor Advisory
http://secunia.com/advisories/25989 Vendor Advisory
http://secunia.com/advisories/27307 Vendor Advisory
http://secunia.com/advisories/27314 Vendor Advisory
http://secunia.com/advisories/29179 Vendor Advisory
http://security.freebsd.org/advisories/FreeBSD-SA-07:04.file.asc
http://security.gentoo.org/glsa/glsa-200703-26.xml
http://security.gentoo.org/glsa/glsa-200710-19.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.512926
http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm
http://www.debian.org/security/2007/dsa-1274
http://www.kb.cert.org/vuls/id/606700 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2007:067
http://www.novell.com/linux/security/advisories/2007_40_file.html
http://www.novell.com/linux/security/advisories/2007_5_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0124.html Vendor Advisory
http://www.securityfocus.com/archive/1/477861/100/0/threaded
http://www.securityfocus.com/archive/1/477950/100/0/threaded
http://www.securityfocus.com/bid/23021
http://www.securitytracker.com/id?1017796
http://www.ubuntu.com/usn/usn-439-1
http://www.vupen.com/english/advisories/2007/1040 Vendor Advisory
http://www.vupen.com/english/advisories/2007/1939 Vendor Advisory
https://bugs.gentoo.org/show_bug.cgi?id=171452

Track CVE-2007-1536 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-1536), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.