PT-2008-3662 · Princeton University · Wordnet

Jukka Ruohonen

·

Publicado

2008-05-12

·

Atualizado

2017-08-08

·

CVE-2008-2149

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wordnet versions 2.0 through 3.0
Description A stack-based buffer overflow issue exists in the searchwn function, potentially allowing attackers to execute arbitrary code via a long command line option. This issue is unlikely to cross privilege boundaries, except when Wordnet is used as a back end.
Recommendations For versions 2.0 through 3.0, consider restricting the use of the searchwn function until a patch is available. As a temporary workaround, avoid using long command line options with the searchwn function to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-37060
AZL-7422
CVE-2008-2149
DSA-1634-1

Produtos afetados

Wordnet