6.8
CVSSv2

CVE-2008-5660

Published: 17/12/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x prior to 0.5.2 and 2.x prior to 2.24.2 might allow remote malicious users to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome vinagre 2.23.1

gnome vinagre 2.23.2

gnome vinagre 2.24.1

gnome vinagre 0.5.0

gnome vinagre 2.23.4

gnome vinagre 2.23.90

gnome vinagre 2.23.3

gnome vinagre 2.23.3.1

gnome vinagre 0.5.1

gnome vinagre 2.23.92

gnome vinagre 2.23.91

gnome vinagre 2.24.0

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ Vinagre show_error() format string vulnerability 1 *Advisory Information* Title: Vinagre show_error() format string vulnerability Advisory ID: CORE-2008-1127 Advisory URL: wwwcoresecurity ...