CVE-2008-3533
Yelp 2.23.1 - Invalid URI Format String
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.
Vulnerabilidad de cadena de formato en la función window_error de yelp-window.c en yelp de Gnome después de 2.19.90 y antes de 2.24 permite a atacantes remotos ejecutar código de su elección mediante especificadores de formato de cadena en un URI no válido en línea de comandos, como se demostró utilizando yelp en los controladores URI (1) man o (2) ghelp en Firefox, Evolution y otros programas no especificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-07 CVE Reserved
- 2008-08-13 First Exploit
- 2008-08-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31620 | Third Party Advisory | |
http://secunia.com/advisories/31834 | Third Party Advisory | |
http://secunia.com/advisories/32629 | Third Party Advisory | |
http://www.securityfocus.com/bid/30690 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2393 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44449 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32248 | 2008-08-13 | |
http://bugzilla.gnome.org/attachment.cgi?id=115890 | 2024-08-07 | |
http://bugzilla.gnome.org/show_bug.cgi?id=546364 | 2024-08-07 | |
https://bugs.launchpad.net/ubuntu/+source/yelp/+bug/254860 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Yelp Search vendor "Gnome" for product "Yelp" | * | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gnome Search vendor "Gnome" for product "Gnome" | 2.20 Search vendor "Gnome" for product "Gnome" and version "2.20" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gnome Search vendor "Gnome" for product "Gnome" | 2.22 Search vendor "Gnome" for product "Gnome" and version "2.22" | - |
Affected
|