PT-2008-1110 · Gnome · Vinagre

Alfredo Ortega

·

Publicado

2008-12-17

·

Atualizado

2018-10-11

·

CVE-2008-5660

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Vinagre versions prior to 0.5.2 Vinagre versions 2.x prior to 2.24.2
Description The issue is related to a format string vulnerability in the vinagre utils show error function, which may allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response. This could lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely.
Recommendations For Vinagre versions prior to 0.5.2, update to version 0.5.2 or later. For Vinagre versions 2.x prior to 2.24.2, update to version 2.24.2 or later.

Exploit

Correção

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09371
CVE-2008-5660

Produtos afetados

Vinagre