7.5
CVSSv2

CVE-2008-3904

Published: 04/09/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent malicious users to execute arbitrary commands via shell metacharacters in a filename.

Vulnerable Product Search on Vulmon Subscribe to Product

lxde gpicview 0.1.9

lxde lightweight x11 desktop environment

Vendor Advisories

Debian Bug report logs - #498022 gpicview: CVE-2008-3904 arbitrary code execution via crafted file name Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnoco ...
Debian Bug report logs - #495968 gpicview: CVE-2008-3791 insecure temporary file usage Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnocom> Date: Thu ...
Debian Bug report logs - #497005 gpicview not confirms to save images Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnocom> Date: Fri, 29 Aug 2008 06: ...