CVE-2008-5660

Vinagre <0.5.2, <2.24.2 - RCE

Title source: llm

Description

Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textdoswindows
https://www.exploit-db.com/exploits/7401

Scores

EPSS 0.0159
EPSS Percentile 81.4%

Classification

CWE
CWE-134
Status draft

Affected Products (12)

gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre
gnome/vinagre

Timeline

Published Dec 17, 2008
Tracked Since Feb 18, 2026