Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
BID:32682
Info
Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
| Bugtraq ID: | 32682 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5660 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Apr 13 2015 10:19PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 GNOME Vinagre 2.24 GNOME Vinagre 0.5 Gentoo Linux |
| Not Vulnerable: |
GNOME Vinagre 2.24.2 GNOME Vinagre 0.5.2 |
Discussion
Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
Vinagre is prone to a remote format-string vulnerability because it fails to sufficiently sanitize user-supplied input before using it in a formatted-printing function.
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious '.vnc' file.
Successfully exploiting this issue will allow attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely crash the application.
Vinagre is prone to a remote format-string vulnerability because it fails to sufficiently sanitize user-supplied input before using it in a formatted-printing function.
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious '.vnc' file.
Successfully exploiting this issue will allow attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely crash the application.
Exploit / POC
Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.10 lpia
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.1
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Mandriva Linux Mandrake 2009.0
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS i386
Mandriva Linux Mandrake 2009.0 x86_64
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 8.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS lpia
GNOME Vinagre 0.5
GNOME Vinagre 2.24
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu vinagre_2.24.1-0ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_2.24.1-0ubuntu1.1_ lpia.deb
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva vinagre-0.5.0-1.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva vinagre-0.5.0-1.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu vinagre_2.24.1-0ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_2.24.1-0ubuntu1.1_ sparc.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu vinagre_0.5.1-0ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_0.5.1-0ubuntu1.1_p owerpc.deb
Mandriva Linux Mandrake 2009.0
-
Mandriva vinagre-2.24.0-1.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu vinagre_2.24.1-0ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_2.24.1-0ubuntu1.1_ powerpc.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu vinagre_2.24.1-0ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/v/vinagre/vinagre_2.24.1-0 ubuntu1.1_i386.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu vinagre_0.5.1-0ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_0.5.1-0ubuntu1.1_s parc.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu vinagre_0.5.1-0ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/v/vinagre/vinagre_0.5.1-0u buntu1.1_i386.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva vinagre-2.24.0-1.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu vinagre_0.5.1-0ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/v/vinagre/vinagre_0.5.1-0u buntu1.1_amd64.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu vinagre_2.24.1-0ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/v/vinagre/vinagre_2.24.1-0 ubuntu1.1_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu vinagre_0.5.1-0ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/v/vinagre/vinagre_0.5.1-0ubuntu1.1_l pia.deb
GNOME Vinagre 0.5
-
GNOME vinagre-0.5.2.tar.bz2
http://ftp.gnome.org/pub/GNOME/sources/vinagre/0.5/vinagre-0.5.2.tar.b z2
GNOME Vinagre 2.24
-
GNOME vinagre-2.24.2.tar.bz2
http://ftp.gnome.org/pub/GNOME/sources/vinagre/2.24/vinagre-2.24.2.tar .bz2
References
Vinagre 'vinagre_utils_show_error()' Function Format String Vulnerability
References:
References:
- Vinagre Changelog (GNOME)
- Vinagre Homepage (GNOME)
- Vinagre show_error() format string vulnerability (CORE Security Technologies)
- CORE-2008-1127 - Vinagre show_error() format string vulnerability (CORE Security Technologies Advisories
)