CVE-2008-3533: Critical severity yelp vulnerability
Format string vulnerability in the windowerror function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3533?
CVE-2008-3533 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2008-3533?
To fix CVE-2008-3533, upgrade to versions of Yelp that are 2.24 or later.
What systems are affected by CVE-2008-3533?
CVE-2008-3533 affects Gnome Yelp versions from 2.19.90 to 2.24.
Can CVE-2008-3533 be exploited remotely?
Yes, CVE-2008-3533 can be exploited remotely via specially crafted URIs.
What type of vulnerability is CVE-2008-3533?
CVE-2008-3533 is a format string vulnerability that can lead to arbitrary code execution.