CVE Vulnerabilities

CVE-2009-4881

Published: Jun 01, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.

Affected Software

NameVendorStart VersionEnd Version
GlibcGnu*2.9 (including)
GlibcGnu1.00 (including)1.00 (including)
GlibcGnu1.01 (including)1.01 (including)
GlibcGnu1.02 (including)1.02 (including)
GlibcGnu1.03 (including)1.03 (including)
GlibcGnu1.04 (including)1.04 (including)
GlibcGnu1.05 (including)1.05 (including)
GlibcGnu1.06 (including)1.06 (including)
GlibcGnu1.07 (including)1.07 (including)
GlibcGnu1.08 (including)1.08 (including)
GlibcGnu1.09 (including)1.09 (including)
GlibcGnu2.0 (including)2.0 (including)
GlibcGnu2.0.1 (including)2.0.1 (including)
GlibcGnu2.0.2 (including)2.0.2 (including)
GlibcGnu2.0.3 (including)2.0.3 (including)
GlibcGnu2.0.4 (including)2.0.4 (including)
GlibcGnu2.0.5 (including)2.0.5 (including)
GlibcGnu2.0.6 (including)2.0.6 (including)
GlibcGnu2.1 (including)2.1 (including)
GlibcGnu2.1.1 (including)2.1.1 (including)
GlibcGnu2.1.1.6 (including)2.1.1.6 (including)
GlibcGnu2.1.2 (including)2.1.2 (including)
GlibcGnu2.1.3 (including)2.1.3 (including)
GlibcGnu2.1.3.10 (including)2.1.3.10 (including)
GlibcGnu2.1.9 (including)2.1.9 (including)
GlibcGnu2.2 (including)2.2 (including)
GlibcGnu2.2.1 (including)2.2.1 (including)
GlibcGnu2.2.2 (including)2.2.2 (including)
GlibcGnu2.2.3 (including)2.2.3 (including)
GlibcGnu2.2.4 (including)2.2.4 (including)
GlibcGnu2.2.5 (including)2.2.5 (including)
GlibcGnu2.3 (including)2.3 (including)
GlibcGnu2.3.1 (including)2.3.1 (including)
GlibcGnu2.3.2 (including)2.3.2 (including)
GlibcGnu2.3.3 (including)2.3.3 (including)
GlibcGnu2.3.4 (including)2.3.4 (including)
GlibcGnu2.3.5 (including)2.3.5 (including)
GlibcGnu2.3.6 (including)2.3.6 (including)
GlibcGnu2.3.10 (including)2.3.10 (including)
GlibcGnu2.4 (including)2.4 (including)
GlibcGnu2.5 (including)2.5 (including)
GlibcGnu2.5.1 (including)2.5.1 (including)
GlibcGnu2.6 (including)2.6 (including)
GlibcGnu2.6.1 (including)2.6.1 (including)
GlibcGnu2.7 (including)2.7 (including)
GlibcGnu2.8 (including)2.8 (including)
EglibcUbuntuupstream*
GlibcUbuntujaunty*

References