HIGH · 7.6

CVE-2007-2666

Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (....

Vulnerability Description

Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Notepad\+\+Notepad\+\+<= 4.1.1
ScintillaScintilla1.73

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-2666?

CVE-2007-2666 is a vulnerability with a CVSS score of 7.6 (HIGH). Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (....

How severe is CVE-2007-2666?

CVE-2007-2666 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2666?

Check the references section above for vendor advisories and patch information. Affected products include: Notepad\+\+ Notepad\+\+, Scintilla Scintilla.