CVE-2008-3533
yelp - format string vulnerability
EPSS 19.4%
Description
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.
How to fix CVE-2008-3533
To remediate CVE-2008-3533, upgrade the affected package to a fixed version below.
- Debian/yelp—upgrade to 2.22.1-4 or later
- Debian/yelp—upgrade to 2.22.1-3+lenny2 or later
Is CVE-2008-3533 being exploited?
Moderate — EPSS is 19.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.22.1-4
- from 0, < 2.22.1-3+lenny2