6.8

CVE-2007-6183

Exploit
Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows context-dependent attackers to execute arbitrary code via format string specifiers in the message parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby Gnome2Ruby Gnome2 Version0.16.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.38% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453689
http://bugs.gentoo.org/show_bug.cgi?id=200623
http://em386.blogspot.com/2007/11/your-favorite-better-than-c-scripting.html
http://osvdb.org/40774
http://ruby-gnome2.svn.sourceforge.net/viewvc/ruby-gnome2/ruby-gnome2/trunk/gtk/src/rbgtkmessagedialog.c?view=log
Exploit
http://secunia.com/advisories/27825
http://secunia.com/advisories/27975
http://secunia.com/advisories/28022
http://secunia.com/advisories/28060
http://security.gentoo.org/glsa/glsa-200712-09.xml
http://securityreason.com/securityalert/3407
http://www.debian.org/security/2007/dsa-1431
http://www.mandriva.com/security/advisories?name=MDVSA-2008:033
http://www.securityfocus.com/archive/1/484240/100/0/threaded
http://www.securityfocus.com/bid/26616
http://www.vupen.com/english/advisories/2007/4022
https://bugzilla.redhat.com/show_bug.cgi?id=402871
https://exchange.xforce.ibmcloud.com/vulnerabilities/38757
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00214.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00251.html