CVE-2008-7185
published 2009-09-08CVE-2008-7185: GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
3.06%
85.9th percentile
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rhythmbox | — | — |
| gnome | rhythmbox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cp42-6q89-8m7p: GNOME Rhythmbox 0
ghsa_unreviewed·2022-05-14
CVE-2008-7185 [MEDIUM] CWE-20 GHSA-cp42-6q89-8m7p: GNOME Rhythmbox 0
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.
OSV
CVE-2008-7185: GNOME Rhythmbox 0
osv·2009-09-08·CVSS 4.3
CVE-2008-7185 [MEDIUM] CVE-2008-7185: GNOME Rhythmbox 0
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.
Debian
CVE-2008-7185: rhythmbox - GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (seg...
vendor_debian·2008·CVSS 4.3
CVE-2008-7185 [MEDIUM] CVE-2008-7185: rhythmbox - GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (seg...
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.org/0806-advisories/rhythmbox-dos.txthttp://www.securityfocus.com/archive/1/493683/100/0/threadedhttp://www.securityfocus.com/archive/1/493809/100/0/threadedhttp://www.securityfocus.com/bid/29958https://exchange.xforce.ibmcloud.com/vulnerabilities/43436http://packetstormsecurity.org/0806-advisories/rhythmbox-dos.txthttp://www.securityfocus.com/archive/1/493683/100/0/threadedhttp://www.securityfocus.com/archive/1/493809/100/0/threadedhttp://www.securityfocus.com/bid/29958https://exchange.xforce.ibmcloud.com/vulnerabilities/43436
2009-09-08
Published