Lucene search

K
ubuntuUbuntuUSN-638-1
HistoryAug 27, 2008 - 12:00 a.m.

Yelp vulnerability

2008-08-2700:00:00
ubuntu.com
29

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.078

Percentile

94.3%

Releases

  • Ubuntu 8.04
  • Ubuntu 7.10

Packages

  • yelp -

Details

Aaron Grattafiori discovered that the Gnome Help Viewer did not
handle format strings correctly when displaying certain error messages.
If a user were tricked into opening a specially crafted URI, a remote
attacker could execute arbitrary code with user privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu8.04noarchyelp< 2.22.1-0ubuntu2.8.04.3UNKNOWN
Ubuntu7.10noarchyelp< 2.20.0-0ubuntu3.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.078

Percentile

94.3%