Back

LOW

security flaw

Published May 25, 2005

Description

Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 25, 2005
Updated Aug 7, 2024
Reserved May 20, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 20, 2005