Vulnerability Description
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Notepad\+\+ | Notepad\+\+ | <= 4.1.1 |
| Scintilla | Scintilla | 1.73 |
Related Weaknesses (CWE)
References
- http://osvdb.org/36007
- http://scintilla.cvs.sourceforge.net/scintilla/scintilla/src/LexRuby.cxx?view=lo
- http://secunia.com/advisories/25245Vendor Advisory
- http://secunia.com/advisories/25327
- http://www.securityfocus.com/archive/1/468529/100/0/threaded
- http://www.securityfocus.com/archive/1/469348/100/100/threaded
- http://www.securityfocus.com/bid/23961
- http://www.vupen.com/english/advisories/2007/1794Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1867Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34269
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34372
- https://www.exploit-db.com/exploits/3912
- http://osvdb.org/36007
- http://scintilla.cvs.sourceforge.net/scintilla/scintilla/src/LexRuby.cxx?view=lo
- http://secunia.com/advisories/25245Vendor Advisory
FAQ
What is CVE-2007-2666?
CVE-2007-2666 is a vulnerability with a CVSS score of 7.6 (HIGH). Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (....
How severe is CVE-2007-2666?
CVE-2007-2666 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2666?
Check the references section above for vendor advisories and patch information. Affected products include: Notepad\+\+ Notepad\+\+, Scintilla Scintilla.