FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-1719

This CVE name corresponds to:

Entered Topic
2007-04-08 mcweject -- exploitable buffer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-1719
Phase Assigned(20070327)

Description

Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.

References

Source Reference
MILW0RM 3578
VUPEN ADV-2007-1125
SECUNIA 24641
XF freebsd-eject-bo(33212)
XF bsd-mcweject-bo(33212)