VDB
CVE-2008-3908
CVE-2008-3908
PUBLISHED
CVSS 10 CRITICAL
Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.
EPSS 2.93% · 86.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
2.93%
86.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| princeton_university | wordnet | 3.0 |
Timeline
- Sep 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 30958 vdb
- 32184 third-party-advisory
- http://www.ocert.org/analysis/2008-014/wordnet.patch url
- wordnet-binsrch-search-bo(44851) vdb
- 20080901 [oCERT-2008-014] WordNet stack and heap overflows mailing-list
- http://www.ocert.org/advisories/ocert-2008-014.html url
- wordnet-wninit-bo(44850) vdb
- http://www.ocert.org/analysis/2008-014/analysis.txt url
- 4217 third-party-advisory
- GLSA-200810-01 vendor-advisory
- wordnet-morphinit-bo(44849) vdb
- wordnet-morph-search-bo(44848) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-3908 advisory