vendor:
Eye of Gnome
by:
SecurityFocus
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: Eye of Gnome
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: o:gnome:eog
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2002
GNOME Eye of Gnome (EOG) image viewer Format String Vulnerability
GNOME Eye of Gnome (EOG) image viewer is prone to a format string vulnerability. This condition may lead to execution of arbitrary code if malicious format specifiers are supplied to the program via the command line. As some utilities may be configured to invoke EOG as the handler for images through a mailcap entry, this may allow for local privilege escalation or possibly remote exploitation.
Mitigation:
Users should avoid using EOG to open untrusted files.