~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2008-3533

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2008-08-18
2
 
Candidate: CVE-2008-3533
3
 
References: 
4
 
 https://usn.ubuntu.com/usn/usn-638-1
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3533
6
 
Description:
7
 
 Format string vulnerability in the window_error function in yelp-window.c
8
 
 in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to
9
 
 execute arbitrary code via format string specifiers in an invalid URI on
10
 
 the command line, as demonstrated by use of yelp within (1) man or (2)
11
 
 ghelp URI handlers in Firefox, Evolution, and unspecified other programs.
12
 
Ubuntu-Description: 
13
 
Notes: 
14
 
Bugs: 
15
 
 https://bugs.launchpad.net/ubuntu/hardy/+source/yelp/+bug/254860
16
 
Priority: low
17
 
Discovered-by: Aaron Grattafiori
18
 
Assigned-to: kees
19
 
 
20
 
Patches_yelp:
21
 
upstream_yelp: pending
22
 
dapper_yelp: not-affected
23
 
feisty_yelp: not-affected
24
 
gutsy_yelp: released (2.20.0-0ubuntu3.1)
25
 
hardy_yelp: released (2.22.1-0ubuntu2.8.04.3)
26
 
devel_yelp: not-affected
27