PT-2008-1096 · Gnome+2 · Ghelp+4

Aaron Grattafiori

+1

·

Published

2008-08-18

·

Updated

2024-11-19

·

CVE-2008-3533

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions yelp versions after 2.19.90 and before 2.24 yelp versions prior to 2.22.1-r2
Description The issue allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line. This can be demonstrated by the use of yelp within man or ghelp URI handlers in various programs, including Firefox and Evolution. The vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations For yelp versions after 2.19.90 and before 2.24, update to a version 2.24 or later. For yelp versions prior to 2.22.1-r2, update to version 2.22.1-r2 or later. As a temporary workaround, consider restricting the use of yelp within URI handlers until a patch is available.

Exploit

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09351
CVE-2008-3533
DTSA-154-1

Affected Products

Evolution
Firefox
Ghelp
Man
Yelp