PT-2014-2265 · Gnu+3 · Glibc+3
Stefan Cornelius
·
Publicado
2012-07-18
·
Atualizado
2019-04-22
·
CVE-2012-3404
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
glibc version 2.12
Description
The issue is related to the vfprintf function in the GNU C Library, which does not properly calculate a buffer length. This allows attackers to bypass the FORTIFY SOURCE format-string protection mechanism, potentially causing a denial of service due to stack corruption and crash. The attack is context-dependent and involves the use of a format string with positional parameters and many format specifiers.
Recommendations
For glibc version 2.12, consider applying a patch or updating to a newer version that addresses this issue, as the current version does not properly handle buffer length calculations in the vfprintf function.
Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Suse
Glibc