GNOME Eye Of Gnome Format String Vulnerability
BID:7121
Info
GNOME Eye Of Gnome Format String Vulnerability
| Bugtraq ID: | 7121 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0165 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 28 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this issue is credited to Diego Kelyacoubian, Javier Kohen, Alberto Solino, and Juan Vera from Core Security Technologies. |
| Vulnerable: |
GNOME eog 2.2 .0 GNOME eog 1.1.4 GNOME eog 1.1.3 GNOME eog 1.1.2 GNOME eog 1.1.1 GNOME eog 1.0.4 GNOME eog 1.0.3 GNOME eog 1.0.2 GNOME eog 1.0.1 GNOME eog 1.0 .0 |
| Not Vulnerable: |
GNOME eog 2.2.1 |
Discussion
GNOME Eye Of Gnome Format String Vulnerability
GNOME Eye of Gnome (EOG) image viewer is prone to a format string vulnerability. This condition may lead to execution of arbitrary code if malicious format specifiers are supplied to the program via the command line. As some utilities may be configured to invoke EOG as the handler for images through a mailcap entry, this may allow for local privilege escalation or possibly remote exploitation.
GNOME Eye of Gnome (EOG) image viewer is prone to a format string vulnerability. This condition may lead to execution of arbitrary code if malicious format specifiers are supplied to the program via the command line. As some utilities may be configured to invoke EOG as the handler for images through a mailcap entry, this may allow for local privilege escalation or possibly remote exploitation.
Exploit / POC
GNOME Eye Of Gnome Format String Vulnerability
The following proof of concept was provided:
$ /usr/bin/eog this_is_an_invalid_file_%n%n
The following proof of concept was provided:
$ /usr/bin/eog this_is_an_invalid_file_%n%n
Solution / Fix
GNOME Eye Of Gnome Format String Vulnerability
Solution:
The vendor has addressed this issue in Eye of Gnome version 2.2.1. Users are advised to upgrade.
GNOME eog 1.0 .0
GNOME eog 1.0.1
GNOME eog 1.0.2
GNOME eog 1.0.3
GNOME eog 1.0.4
GNOME eog 1.1.1
GNOME eog 1.1.2
GNOME eog 1.1.3
GNOME eog 1.1.4
GNOME eog 2.2 .0
Solution:
The vendor has addressed this issue in Eye of Gnome version 2.2.1. Users are advised to upgrade.
GNOME eog 1.0 .0
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.0.1
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.0.2
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/ -
Mandrake eog-1.0.2-1.1mdk.i586.rpm
Mandrake Corporate Server 2.1.
http://www.mandrakesecure.net/en/ftp.php -
Mandrake eog-1.0.2-1.1mdk.i586.rpm
Mandrake Linux 9.0.
http://www.mandrakesecure.net/en/ftp.php -
Red Hat eog-1.0.2-5.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/eog-1.0.2-5.i386.rpm
GNOME eog 1.0.3
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.0.4
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.1.1
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.1.2
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.1.3
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 1.1.4
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/
GNOME eog 2.2 .0
-
GNOME eog 2.2.1
ftp://ftp.gnome.org/pub/GNOME/sources/eog/2.2/ -
Mandrake eog-2.2.0-1.1mdk.i586.rpm
Mandrake Linux 9.1.
http://www.mandrakesecure.net/en/ftp.php -
Mandrake eog-2.2.0-1.1mdk.ppc.rpm
Mandrake Linux 9.1/PPC.
http://www.mandrakesecure.net/en/ftp.php -
Red Hat eog-2.2.0-2.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/eog-2.2.0-2.i386.rpm -
Red Hat eog-debuginfo-2.2.0-2.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/eog-debuginfo-2.2.0-2.i386.rpm