Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11421

Опубликовано: 18 июл. 2017
Источник: debian
EPSS Низкий

Описание

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnome-exe-thumbnailerfixed0.9.5-1package
gnome-exe-thumbnailerfixed0.9.4-2+deb9u1stretchpackage

Примечания

  • http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html

  • https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5

EPSS

Процентиль: 25%
0.00085
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

CVSS3: 7.8
redhat
больше 8 лет назад

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

CVSS3: 7.8
nvd
больше 8 лет назад

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

CVSS3: 7.8
github
больше 3 лет назад

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

EPSS

Процентиль: 25%
0.00085
Низкий