PublicDate: 2008-09-11 01:13:00 UTC Candidate: CVE-2008-3971 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3971 Description: Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported using a configuration file, but that vector does not have a scenario that crosses privilege boundaries. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_gmanedit: upstream_gmanedit: released (0.4.1-1.1) dapper_gmanedit: ignored (reached end-of-life) feisty_gmanedit: needed (reached end-of-life) gutsy_gmanedit: needed (reached end-of-life) hardy_gmanedit: DNE intrepid_gmanedit: not-affected (0.4.1-1.1) jaunty_gmanedit: not-affected (0.4.1-1.1) karmic_gmanedit: not-affected (0.4.1-1.1) devel_gmanedit: not-affected (0.4.1-1.1)