« Volver al listado

CVE-2008-1688

Estado: ModificadaAlta (7.5)—

Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1688",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-04-09T19:05:00.000",
  "references": [
    {
      "url": "http://osvdb.org/44272",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29671",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29729",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/04/07/1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/04/07/3",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28688",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1151/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41704",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/44272",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29671",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29729",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/04/07/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2008/04/07/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28688",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1151/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41704",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option.  NOTE: it is not clear when this issue crosses privilege boundaries."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en GNU m4 versiones anteriores a 1.4.11 podría permitir a  atacantes dependientes de contexto ejecutar código se su elección, relacionado con el manejo no apropiado de nombres de ficheros específicados con la opción -F.\r\nNOTA: no está claro cuando esta cuestión cruza fronteras de privilegios.\r\n\r\n"
    }
  ],
  "lastModified": "2026-06-16T22:52:16.403",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5157211A-80A7-4694-9D45-E1C4CA9DA2C6"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E10A3A6-8DC0-4BFD-8C4F-4B6B7C5EC03B"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77C4D372-B593-4AF4-A2C1-A5F1657B28EE"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "964FCBD7-B697-4D9A-AD73-F5ED3631FBB4"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BE99BE1-1956-41DB-8E9C-684D3040CEAC"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96348B9C-BB73-404D-8A68-0A96B793BC3D"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F6DD41B-D8EF-4D1E-B939-9CB0D85D8217"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C62D0160-F302-43A4-A244-DFD92BC9FD49"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "886BBA7D-DE20-4A47-9896-E71BA25E9205"
            },
            {
              "criteria": "cpe:2.3:a:gnu:m4:1.4.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AF0E0A6-401D-4306-88EC-5FFD207C39BF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Red Hat does not consider this to be a security issue.  After careful analysis of this issue the Red Hat Security Response Team has determined that this bug has no security impact outside of expected m4 behavior.",
      "lastModified": "2008-04-15T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}