Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Patrick J. Volkerding

#18050of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2008-3233
7.5
2008-04-09
Gnu · Gnu M4 · CVE-2008-1687
**Name of the Vulnerable Software and Affected Versions** GNU m4 versions prior to 1.4.11 **Description** The issue concerns the maketemp and mkstemp builtin functions in GNU m4, which do not quote their output when a file is created. This could allow attackers to trigger a macro expansion, potentially leading to the use of an incorrect filename. **Recommendations** For GNU m4 versions prior to 1.4.11, update to version 1.4.11 or later to resolve the issue.
PT-2008-3234
7.5
2008-04-09
Gnu · Gnu M4 · CVE-2008-1688
**Name of the Vulnerable Software and Affected Versions** GNU m4 versions prior to 1.4.11 **Description** The issue is related to improper handling of filenames specified with the -F option, which might allow context-dependent attackers to execute arbitrary code. It is not clear when this issue crosses privilege boundaries. **Recommendations** For versions prior to 1.4.11, update to version 1.4.11 or later to resolve the issue.