Lucene search

K
cveCanonicalCVE-2008-3533
HistoryAug 18, 2008 - 5:41 p.m.

CVE-2008-3533

2008-08-1817:41:00
CWE-134
canonical
web.nvd.nist.gov
34
cve-2008-3533
format string vulnerability
remote code execution
yelp
gnome
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.078

Percentile

94.3%

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

Affected configurations

Nvd
Node
gnomeyelp
Node
gnomegnomeMatch2.20
OR
gnomegnomeMatch2.22
VendorProductVersionCPE
gnomeyelp*cpe:2.3:a:gnome:yelp:*:*:*:*:*:*:*:*
gnomegnome2.20cpe:2.3:a:gnome:gnome:2.20:*:*:*:*:*:*:*
gnomegnome2.22cpe:2.3:a:gnome:gnome:2.22:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.078

Percentile

94.3%