Vulnerability Name: | CVE-2008-3533 (CCN-44449) | ||||||||||||
Assigned: | 2008-08-05 | ||||||||||||
Published: | 2008-08-05 | ||||||||||||
Updated: | 2017-08-08 | ||||||||||||
Summary: | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-134 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: CONFIRM Type: Exploit http://bugzilla.gnome.org/attachment.cgi?id=115890 Source: CCN Type: Gnome Bugzilla Bug 546364 yelp format string vulnerabilty Source: CONFIRM Type: Exploit, Patch http://bugzilla.gnome.org/show_bug.cgi?id=546364 Source: MITRE Type: CNA CVE-2008-3533 Source: SUSE Type: UNKNOWN SUSE-SR:2008:024 Source: CCN Type: GNOME Web site Yelp Source: CCN Type: SA31465 Yelp Invalid URI Format String Vulnerability Source: SECUNIA Type: Vendor Advisory 31465 Source: SECUNIA Type: UNKNOWN 31620 Source: SECUNIA Type: UNKNOWN 31834 Source: SECUNIA Type: UNKNOWN 32629 Source: CCN Type: GLSA-200809-01 yelp: User-assisted execution of arbitrary code Source: MANDRIVA Type: UNKNOWN MDVSA-2008:175 Source: CCN Type: OSVDB ID: 47513 Yelp yelp-window.c gtk_message_dialog Crafted URI Format String Source: BID Type: UNKNOWN 30690 Source: CCN Type: BID-30690 Yelp Invalid URI Format String Vulnerability Source: CCN Type: USN-638-1 Yelp vulnerability Source: UBUNTU Type: UNKNOWN USN-638-1 Source: VUPEN Type: UNKNOWN ADV-2008-2393 Source: CONFIRM Type: Exploit, Patch https://bugs.launchpad.net/ubuntu/+source/yelp/+bug/254860 Source: XF Type: UNKNOWN yelp-uri-format-string(44449) Source: XF Type: UNKNOWN yelp-uri-format-string(44449) Source: FEDORA Type: UNKNOWN FEDORA-2008-7293 Source: SUSE Type: SUSE-SR:2008:024 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |