CVE-2008-0668

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.

公开: 2008-02-11 最后更新: 2026-06-16 分配方: [email protected] 来源: [email protected]

结论预警: CVE-2008-0668 综合评估为高风险(66.5/100):CVSS 技术影响为严重级,利用概率偏高(EPSS 4.98%,百分位 91%) 核心证据: EPSS 显示该漏洞近期被利用的可能性处于高位。 强制指令: 被利用概率偏高—请排查暴露面并优先安排修补。

风险随态势动态变化;本站持续评估并同步更新本页展示内容。

CVE-2008-0668 的 EPSS(利用预测评分)

EPSS 日更估计相对被利用可能性;百分位表示该 CVE 在已评分漏洞中的相对排名(越高表示相对更严重)。

# 日期 旧 EPSS 分数 新 EPSS 分数 变化(新 − 旧)
1 2026-06-15 7.51% 4.98% -2.53%
2 2026-03-08 6.66% 7.51% +0.85%
3 2025-03-30 6.66%

完整 EPSS 历史 (共 15 条)

CVE-2008-0668 的 CVSS 指标

该 CVE 的 CVSS 指标。

底座分 版本 严重度 向量 可利用性 影响 分数来源
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C 点击展开
访问路径 (AV:N)
只要路由可达,即可从远端发起利用。
访问复杂度 (AC:M)
需要若干有利条件,但不至于“千年一遇”。
认证 (AU:N)
全程无需有效身份。
机密性影响 (C:C)
机密性被完全破坏。
完整性影响 (I:C)
完整性被完全破坏。
可用性影响 (A:C)
可用性被完全破坏。
8.6 10.0 [email protected]

CVE-2008-0668 的弱点枚举

CVE-2008-0668 的 OS 跟踪

vendor priority summary link
debian medium CVE-2008-0668 medium priority: Debian including 1 source packages (gnumeric), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2008-0668
gentoo normal CVE-2008-0668: 1 GLSA(s) (200802-05), 1 atom(s) (app-office/gnumeric); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-0668
redhat high https://access.redhat.com/security/cve/CVE-2008-0668
ubuntu medium CVE-2008-0668 medium priority: Ubuntu including 1 source packages (gnumeric), 5 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): released 4, not-affected 1. https://ubuntu.com/security/CVE-2008-0668

CVE-2008-0668 的影响软件 / 配置

厂商 产品 版本 原始 CPE
gnome gnumeric <= 1.7.91 cpe:2.3:a:gnome:gnumeric:*:*:*:*:*:*:*:*

CVE-2008-0668 的参考链接

URL 标签
http://bugs.gentoo.org/show_bug.cgi?id=208356
http://bugzilla.gnome.org/show_bug.cgi?id=505330
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html
http://secunia.com/advisories/28725/ Vendor Advisory
http://secunia.com/advisories/28799 Patch Vendor Advisory
http://secunia.com/advisories/28948
http://secunia.com/advisories/29702
http://secunia.com/advisories/29896
http://secunia.com/advisories/31339
http://security.gentoo.org/glsa/glsa-200802-05.xml
http://www.debian.org/security/2008/dsa-1546
http://www.gnome.org/projects/gnumeric/announcements/1.8/gnumeric-1.8.1.shtml Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2008:056
http://www.securityfocus.com/bid/27536
http://www.ubuntu.com/usn/usn-604-1
http://www.vupen.com/english/advisories/2008/0462
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00114.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00227.html
cvelogic Threat Intelligence