Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
BID:26616
Info
Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
| Bugtraq ID: | 26616 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6183 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 27 2007 12:00AM |
| Updated: | Apr 13 2015 09:45PM |
| Credit: | Chris Rohlf is credited with the discovery of this issue. |
| Vulnerable: |
Ruby-GNOME2 Ruby-GNOME2 0.16 Ruby-GNOME2 Ruby-GNOME2 0.15 Ruby-GNOME2 Ruby-GNOME2 0.12 Redhat Fedora 7 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
The Ruby-GNOME2 library is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
An attacker can exploit this issue to execute arbitrary machine code in the context of an application using the affected library. A successful attack will compromise the application. Failed attempts may cause denial-of-service conditions.
This issue affects Ruby-GNOME2 0.16.0; other version may be also vulnerable.
The Ruby-GNOME2 library is prone to a format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
An attacker can exploit this issue to execute arbitrary machine code in the context of an application using the affected library. A successful attack will compromise the application. Failed attempts may cause denial-of-service conditions.
This issue affects Ruby-GNOME2 0.16.0; other version may be also vulnerable.
Exploit / POC
Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
Solution:
The vendor has released a fix in the SVN repository. Please see the references for more information.
Solution:
The vendor has released a fix in the SVN repository. Please see the references for more information.
References
Ruby-GNOME2 Gtk::MessageDialog.new Function Format String Vulnerability
References:
References:
- Ruby-GNOME2 Project Website (Ruby-GNOME2)
- Your favorite better than C scripting language is probably implemented in C (Chris Rohlf)