Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37061.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-37061
Upstream
Published
2008-09-04T17:41:00Z
Modified
2026-04-21T04:28:08.065647Z
Summary
CVE-2008-3908 affecting package wordnet for versions less than 3.0-43
Details

Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.

References

Affected packages

Azure Linux:3 / wordnet

Package

Name
wordnet
Purl
pkg:rpm/azure-linux/wordnet

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0-43

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37061.json"