Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as...
Vulnerability Description
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2666
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2007/1794
- http://www.securityfocus.com/archive/1/468529/100/0/threaded
- https://www.exploit-db.com/exploits/3912
- http://secunia.com/advisories/25327
- http://www.vupen.com/english/advisories/2007/1867
- http://www.securityfocus.com/archive/1/469348/100/100/threaded
- http://www.securityfocus.com/bid/23961
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34269
- http://scintilla.cvs.sourceforge.net/scintilla/scintilla/src/LexRuby.cxx?view=log#rev1.13
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34372
- http://osvdb.org/36007
- http://secunia.com/advisories/25245
Affected Vendor
notepad\+\+
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.