PT-2008-1096 · Gnome+2 · Ghelp+4
Aaron Grattafiori
+1
·
Published
2008-08-18
·
Updated
2024-11-19
·
CVE-2008-3533
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
yelp versions after 2.19.90 and before 2.24
yelp versions prior to 2.22.1-r2
Description
The issue allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line. This can be demonstrated by the use of yelp within man or ghelp URI handlers in various programs, including Firefox and Evolution. The vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations
For yelp versions after 2.19.90 and before 2.24, update to a version 2.24 or later.
For yelp versions prior to 2.22.1-r2, update to version 2.22.1-r2 or later.
As a temporary workaround, consider restricting the use of yelp within URI handlers until a patch is available.
Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolution
Firefox
Ghelp
Man
Yelp