CVE Vulnerabilities

CVE-2008-1391

Published: Mar 27, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 6.0 (including) 6.0 (including)
Freebsd Freebsd 6.0-release (including) 6.0-release (including)
Freebsd Freebsd 6.0-stable (including) 6.0-stable (including)
Freebsd Freebsd 6.0_p5_release (including) 6.0_p5_release (including)
Freebsd Freebsd 7.0 (including) 7.0 (including)
Freebsd Freebsd 7.0-pre-release (including) 7.0-pre-release (including)
Freebsd Freebsd 7.0_beta4 (including) 7.0_beta4 (including)
Freebsd Freebsd 7.0_releng (including) 7.0_releng (including)
Netbsd Netbsd 4.0 (including) 4.0 (including)
Eglibc Ubuntu karmic *
Eglibc Ubuntu upstream *
Glibc Ubuntu dapper *
Glibc Ubuntu hardy *
Glibc Ubuntu intrepid *
Glibc Ubuntu jaunty *
Glibc Ubuntu upstream *

References