LWN.net Logo

wordnet: buffer overflows

Package(s):wordnet CVE #(s):CVE-2008-3908
Created:September 16, 2008 Updated:October 7, 2008
Description: From the CVE entry: Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.
Alerts:
Gentoo 200810-01 2008-10-07
Mandriva MDVSA-2008:182-1 2008-09-15

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds