REDHAT-BUG-1121497: High severity Snoopy Snoopy library vulnerability

Published Jul 21, 2014
·
Updated

CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27

The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).

It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:

http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/

And fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28

This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).

However, the CVE-2014-5008 fix was also incomplete:

https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706

This was fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29

And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).

References:

http://www.openwall.com/lists/oss-security/2014/07/09/11

Affected Software

1 affected component
Snoopy Snoopy library

Event History

Jul 21, 2014
Data Sourced
via Red Hat·06:11 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1121497?

The severity of REDHAT-BUG-1121497 is categorized as high due to the potential for command execution vulnerabilities.

2

How do I fix REDHAT-BUG-1121497?

To fix REDHAT-BUG-1121497, update the Snoopy library to the latest version that contains the security patch.

3

What vulnerability does REDHAT-BUG-1121497 address?

REDHAT-BUG-1121497 addresses a command execution flaw in the Snoopy library as documented in CVE-2008-4796.

4

Which versions of Snoopy library are affected by REDHAT-BUG-1121497?

All versions of the Snoopy library prior to the patch that addresses the flaw in REDHAT-BUG-1121497 are affected.

5

Is REDHAT-BUG-1121497 associated with any known exploits?

Yes, REDHAT-BUG-1121497 is associated with known exploits that can leverage command execution vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203