CVE-2008-1568: Input Validation
Published Mar 31, 2008
·Updated
comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.
Affected Software
1 affected component
Comix Comix=3.6.4
Event History
Mar 31, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1568?
CVE-2008-1568 is classified as a medium-severity vulnerability due to its ability to execute arbitrary commands.
2
How do I fix CVE-2008-1568?
To fix CVE-2008-1568, update to a newer version of Comix that includes proper sanitization of filenames with shell metacharacters.
3
What software versions are affected by CVE-2008-1568?
CVE-2008-1568 specifically affects Comix version 3.6.4.
4
What impact does CVE-2008-1568 have on my system?
CVE-2008-1568 allows attackers to execute arbitrary commands, potentially leading to system compromise.
5
Is CVE-2008-1568 exploitative in nature?
Yes, CVE-2008-1568 is exploitative as it enables malicious users to run arbitrary commands on the affected system.