CVE-1999-0719: Medium severity GNU Gnumeric vulnerability
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Gnome Gnumeric Guile pluginfrom your environment.Uninstall or remove the Guile plugin from the Gnumeric installation if it is not required (remove plugin package/files or uninstall the package that provides the Guile plugin).
- Configuration
Disable the Guile plugin in Gnumeric (via the application's plugin manager or configuration) to prevent arbitrary code execution from spreadsheet files.
Gnumeric (Guile plugin) guile_plugin_enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0719?
CVE-1999-0719 is considered a critical vulnerability due to the ability for attackers to execute arbitrary code.
How do I fix CVE-1999-0719?
To fix CVE-1999-0719, you should upgrade to a version of Gnumeric that does not include the vulnerable Guile plugin.
What systems are affected by CVE-1999-0719?
CVE-1999-0719 affects the Gnumeric version 0.27 specifically.
What kind of attacks can exploit CVE-1999-0719?
CVE-1999-0719 can be exploited to execute arbitrary code remotely, allowing attackers to gain unauthorized control over the affected system.
Is there a workaround for CVE-1999-0719?
A temporary workaround for CVE-1999-0719 is to disable the Guile plugin in Gnumeric until an upgrade can be performed.