CVE Vulnerabilities

CVE-2012-4412

Published: Oct 09, 2013 | Modified: Jun 13, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu * 2.17 (including)
Glibc Gnu 2.0 (including) 2.0 (including)
Glibc Gnu 2.0.1 (including) 2.0.1 (including)
Glibc Gnu 2.0.2 (including) 2.0.2 (including)
Glibc Gnu 2.0.3 (including) 2.0.3 (including)
Glibc Gnu 2.0.4 (including) 2.0.4 (including)
Glibc Gnu 2.0.5 (including) 2.0.5 (including)
Glibc Gnu 2.0.6 (including) 2.0.6 (including)
Glibc Gnu 2.1 (including) 2.1 (including)
Glibc Gnu 2.1.1 (including) 2.1.1 (including)
Glibc Gnu 2.1.1.6 (including) 2.1.1.6 (including)
Glibc Gnu 2.1.2 (including) 2.1.2 (including)
Glibc Gnu 2.1.3 (including) 2.1.3 (including)
Glibc Gnu 2.1.9 (including) 2.1.9 (including)
Glibc Gnu 2.10.1 (including) 2.10.1 (including)
Glibc Gnu 2.11 (including) 2.11 (including)
Glibc Gnu 2.11.1 (including) 2.11.1 (including)
Glibc Gnu 2.11.2 (including) 2.11.2 (including)
Glibc Gnu 2.11.3 (including) 2.11.3 (including)
Glibc Gnu 2.12.1 (including) 2.12.1 (including)
Glibc Gnu 2.12.2 (including) 2.12.2 (including)
Glibc Gnu 2.13 (including) 2.13 (including)
Glibc Gnu 2.14 (including) 2.14 (including)
Glibc Gnu 2.14.1 (including) 2.14.1 (including)
Glibc Gnu 2.15 (including) 2.15 (including)
Glibc Gnu 2.16 (including) 2.16 (including)
Eglibc Ubuntu devel *
Eglibc Ubuntu lucid *
Eglibc Ubuntu natty *
Eglibc Ubuntu oneiric *
Eglibc Ubuntu precise *
Eglibc Ubuntu quantal *
Eglibc Ubuntu raring *
Eglibc Ubuntu saucy *
Glibc Ubuntu hardy *

References