|
|
|
Vulnerability Note VU#814557GNOME gedit contains format string vulnerabilityOverviewgedit has a format string vulnerability in some error dialogs that can occur when a file is opened for editing.I. Descriptiongedit is the official text editor of the GNOME desktop environment. gedit 2.10.2 has a format string error in some some error dialogs that can occur when a file is opened for editing. Some of the messages in these dialogs, which can contain the name of the file being opened, are interpreted as format strings. Versions prior to v2.10.2 may also be vulnerable.II. ImpactAn attacker can execute arbitrary code if a user can be coerced to open a file with a particular name.III. SolutionUpgrade to gedit v2.10.3 or later.Systems Affected
References
This issue was discovered by jsk:exworm of www.0xbadexworm.org. This document was written by Hal Burch.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||