>> Yelp URI Processing Remote Format String Vulnerability
Title : Yelp URI Processing Remote Format String Vulnerability VUPEN ID : VUPEN/ADV-2008-2393 CVE ID : CVE-2008-3533 CWE ID : CWE-134
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-18
Technical Description
A vulnerability has been identified in Yelp, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a format string error in the "window_error()" [yelp-window.c] function when processing a malformed URI, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into following a specially crafted link.