CVE-2008-2575
CVE-2008-2575 describes a vulnerability in cbrPager versions prior to 0.9.17, affecting products like fedoraproject cbrpager and jcoppens cbrpager. This flaw allows user-assisted remote attackers to execute arbitrary commands by embedding shell metacharacters within filenames of ZIP (.cbz) or RAR (.cbr) archives. The vulnerability carries a CVSS score of 6.8, indicating a medium severity with a network attack vector, medium attack complexity, and potential for partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage, suggesting it is not a widely targeted vulnerability.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.17CPE matchmatch criteria | cpe:2.3:a:jcoppens:cbrpager:*:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploit Intelligence
Social Chatter
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.