CVE-2008-5660
EPSS 9.1%
Description
Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.
How to fix CVE-2008-5660
To remediate CVE-2008-5660, upgrade the affected package to a fixed version below.
- Debian/vinagre—upgrade to 0.5.1-2 or later
Is CVE-2008-5660 being exploited?
Moderate — EPSS is 9.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.5.1-2