CVE Vulnerabilities

CVE-2012-0864

Published: May 02, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu 2.14 (including) 2.14 (including)
Red Hat Enterprise Linux 5 RedHat glibc-0:2.5-81.el5_8.1 *
Red Hat Enterprise Linux 6 RedHat glibc-0:2.12-1.47.el6_2.9 *
RHEV 3.X Hypervisor and Agents for RHEL-6 RedHat rhev-hypervisor6-0:6.2-20120423.1.el6_2 *
Eglibc Ubuntu devel *
Eglibc Ubuntu lucid *
Eglibc Ubuntu maverick *
Eglibc Ubuntu natty *
Eglibc Ubuntu oneiric *
Glibc Ubuntu hardy *

References