2.6 CVE-2005-1686

 

Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.
https://nvd.nist.gov/vuln/detail/CVE-2005-1686

Categories

CWE-NVD-Other

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:gnome:gedit:2.10.2:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
25688 Gedit 2.x - Filename Format String 2005-05-30 00:00:00

Other (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry


MITRE