PT-2008-5238 · Lxde · Gpicview
Nico Golde
·
Published
2008-09-04
·
Updated
2017-08-08
·
CVE-2008-3904
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LXDE GPicView version 0.1.9
Description
The issue allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. This is due to a problem in the src/main-win.c file of GPicView.
Recommendations
For GPicView version 0.1.9, consider avoiding the use of filenames that contain shell metacharacters until a patch is available. As a temporary workaround, restrict the ability to open files with potentially malicious filenames to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpicview