« Volver al listado

CVE-2008-2149

Estado: ModificadaAlta (7.5)—

Desbordamiento de búfer basado en pila en la función searchwn de Wordnet 2.0, 2.1 y 3.0 podría permitir a atacantes dependientes del contexto ejecutar código de su elección mediante una opción de línea de comandos larga. NOTA: este tema probablemente no cruza límites de privilegios excepto en casos en los que Wordnet se usa como motor interno (back end).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-2149",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-05-12T21:20:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/30242",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31654",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32184",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2008/dsa-1634",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200810-01.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:182",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/29208",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1527/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=211491",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42378",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/30242",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31654",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/32184",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2008/dsa-1634",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200810-01.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:182",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/29208",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1527/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=211491",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42378",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in the searchwn function in Wordnet 2.0, 2.1, and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option.  NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en pila en la función searchwn de Wordnet 2.0, 2.1 y 3.0 podría permitir a atacantes dependientes del contexto ejecutar código de su elección mediante una opción de línea de comandos larga. NOTA: este tema probablemente no cruza límites de privilegios excepto en casos en los que Wordnet se usa como motor interno (back end)."
    }
  ],
  "lastModified": "2026-06-16T22:53:11.893",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wordnet:wordnet:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0161FA05-EC88-497F-A0F0-0BF09BEB2624"
            },
            {
              "criteria": "cpe:2.3:a:wordnet:wordnet:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2E2D3B7-FE7A-44F3-A08A-16C4383DD6A3"
            },
            {
              "criteria": "cpe:2.3:a:wordnet:wordnet:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "678000ED-F5CE-4FFE-B31A-ED94AF77D9D1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}