vendor:
Gnome Panel
by:
Pietro Oliva
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Gnome Panel
Affected Version From: 2.28.0
Affected Version To: 2.28.0
Patch Exists: YES
Related CWE: N/A
CPE: a:gnome:gnome_panel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 9.10
2010
Gnome panel <= 2.28.0 denial of service poc 0-day
This proof-of-concept code creates a backup file of the .gtk-bookmarks file and then appends a large number of 'A' characters to it. Depending on the argument passed to the code, the number of 'A' characters appended can be either 9999 or 99999. This causes the Gnome panel to crash and restart continuously or to become completely unresponsive, respectively.
Mitigation:
Upgrade to the latest version of Gnome panel.