PT-2014-2265 · Gnu+3 · Glibc+3

Stefan Cornelius

·

Publicado

2012-07-18

·

Atualizado

2019-04-22

·

CVE-2012-3404

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions glibc version 2.12
Description The issue is related to the vfprintf function in the GNU C Library, which does not properly calculate a buffer length. This allows attackers to bypass the FORTIFY SOURCE format-string protection mechanism, potentially causing a denial of service due to stack corruption and crash. The attack is context-dependent and involves the use of a format string with positional parameters and many format specifiers.
Recommendations For glibc version 2.12, consider applying a patch or updating to a newer version that addresses this issue, as the current version does not properly handle buffer length calculations in the vfprintf function.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_1098
CVE-2012-3404
DSA-3169-1
RHSA-2012:1098
RHSA-2012:1200
RHSA-2012_1098
SUSE-SU-2012_1666-1
SUSE-SU-2015:0551-1

Produtos afetados

Centos
Red Hat
Suse
Glibc