Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-3533
HistoryAug 18, 2008 - 12:00 a.m.

CVE-2008-3533

2008-08-1800:00:00
ubuntu.com
ubuntu.com
11

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.078

Percentile

94.3%

Format string vulnerability in the window_error function in yelp-window.c
in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to
execute arbitrary code via format string specifiers in an invalid URI on
the command line, as demonstrated by use of yelp within (1) man or (2)
ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu7.10noarchyelp< 2.20.0-0ubuntu3.1UNKNOWN
ubuntu8.04noarchyelp< 2.22.1-0ubuntu2.8.04.3UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.078

Percentile

94.3%