CVE-2008-3971

NameCVE-2008-3971
DescriptionHeap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported using a configuration file, but that vector does not have a scenario that crosses privilege boundaries.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs497835

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gmanedit (PTS)buster0.4.2-7fixed
sid, trixie, bookworm, bullseye0.4.2-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gmaneditsource(unstable)0.4.1-1.1low497835

Notes

[etch] - gmanedit <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems