CVE-2008-3533

yelp < 2.24 - Remote Code Execution via Format String in URI Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3533. PoCs published by Aaron Grattafiori.

AI-analyzed exploit summary This exploit demonstrates a format-string vulnerability in Yelp 2.23.1 by providing malformed input strings that can leak memory contents or crash the application. The PoC includes format specifiers like %08x and %x to trigger the vulnerability.

Description

Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aaron Grattafiori · textdoslinux
https://www.exploit-db.com/exploits/32248

This exploit demonstrates a format-string vulnerability in Yelp 2.23.1 by providing malformed input strings that can leak memory contents or crash the application. The PoC includes format specifiers like %08x and %x to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Yelp 2.23.1
No auth needed
Prerequisites: A vulnerable version of Yelp (2.23.1 or potentially others)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Exploit, Issue Tracking x_refsource_confirm
http://bugzilla.gnome.org/attachment.cgi?id=115890
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31465
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30690
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31620
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-638-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32629
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31834
Exploit, Issue Tracking, Patch x_refsource_confirm
http://bugzilla.gnome.org/show_bug.cgi?id=546364
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2393
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00222.html
Product vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:175

Scores

EPSS 0.1337
EPSS Percentile 94.3%

Details

CWE
CWE-134
Status published
Products (3)
gnome/gnome 2.20
gnome/gnome 2.22
gnome/yelp < 2.24
Published Aug 18, 2008
Tracked Since Feb 18, 2026