CVE-2007-5395
link-grammar - buffer overflow
EPSS 7.0%
Description
Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows remote attackers to execute arbitrary code via a long word, as reachable through the separate_sentence function.
How to fix CVE-2007-5395
To remediate CVE-2007-5395, upgrade the affected package to a fixed version below.
- Debian/link-grammar—upgrade to 4.2.5-1 or later
- Debian/link-grammar—upgrade to 4.2.2-4etch1 or later
Is CVE-2007-5395 being exploited?
Moderate — EPSS is 7.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 4.2.5-1
- from 0, < 4.2.2-4etch1