Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7423.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-7423
Upstream
Published
2008-09-04T17:41:00Z
Modified
2026-04-21T04:38:41.258676Z
Summary
CVE-2008-3908 affecting package wordnet for versions less than 3.0-38
Details

Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.

References

Affected packages

Azure Linux:2 / wordnet

Package

Name
wordnet
Purl
pkg:rpm/azure-linux/wordnet

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0-38

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7423.json"