« Volver al listado

CVE-2008-3908

Estado: ModificadaAlta (10)—

Múltiples desbordamientos de búfer en Princeton WordNet (wn) 3.0 permite a atacantes dependientes de contexto ejecutar código de su elección a través de (1)un argumento largo en la línea de comandos; una variable de entorno (2) WNSEARCHDIR, (3) WNHOME, o (4) WNDBVERSION; o (5) un diccionario user-supplied (también conocido como fichero de datos). NOTA: WordNet no se ejecuta con privilegios especiales, esta cuestión sólo cruza las fronteras de los privilegios cuando WordNet está invocado como un componente de terceros.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3908",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-09-04T17:41:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/32184",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4217",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200810-01.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2008-014.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocert.org/analysis/2008-014/analysis.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocert.org/analysis/2008-014/wordnet.patch",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/495883/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30958",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44848",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44849",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44850",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44851",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32184",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/4217",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200810-01.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocert.org/advisories/ocert-2008-014.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocert.org/analysis/2008-014/analysis.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocert.org/analysis/2008-014/wordnet.patch",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/495883/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30958",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44848",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44849",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44850",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44851",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file).  NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en Princeton WordNet (wn) 3.0 permite a atacantes dependientes de contexto ejecutar código de su elección a través de (1)un argumento largo en la línea de comandos; una variable de entorno (2) WNSEARCHDIR, (3) WNHOME, o (4) WNDBVERSION; o (5) un diccionario user-supplied (también conocido como fichero de datos).\r\nNOTA: WordNet no se ejecuta con privilegios especiales, esta cuestión sólo cruza las fronteras de los privilegios cuando WordNet está invocado como un componente de terceros.\r\n"
    }
  ],
  "lastModified": "2026-06-16T22:56:47.187",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:princeton_university:wordnet:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57EBB860-30D8-4436-B667-D35DF232A716"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}