PT-2005-5558 · Debian+2 · Debian+2

Exworm

+1

·

Published

1970-01-01

·

Updated

2018-10-03

·

CVE-2005-1686

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions gedit versions 2.10.2 and earlier
Description The issue is related to multiple vulnerabilities in the gedit package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. A format string vulnerability in gedit may allow attackers to cause a denial of service via a bin file with format string specifiers in the filename. It has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, allowing for a valid attack that crosses security boundaries.
Recommendations For gedit version 2.10.2 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, avoid using gedit to open files from untrusted sources, especially those with potentially malicious filenames. Restrict access to gedit and its associated files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01350
BDU:2015-01351
BDU:2015-01352
CVE-2005-1686
DSA-753-1
RHSA-2005:499
RHSA-2005_499

Affected Products

Debian
Red Hat
Gedit