Unrated severityNVD Advisory· Published May 20, 2005· Updated Apr 16, 2026
CVE-2005-1686
CVE-2005-1686
Description
Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.
Affected products
1- cpe:2.3:a:gnome:gedit:2.10.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- marc.infonvd
- security.gentoo.org/glsa/glsa-200506-09.xmlnvd
- www.debian.org/security/2005/dsa-753nvd
- www.novell.com/linux/security/advisories/2005_36_sudo.htmlnvd
- www.redhat.com/support/errata/RHSA-2005-499.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1245nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9845nvd
- usn.ubuntu.com/138-1/nvd
News mentions
0No linked articles in our index yet.