PT-2014-2266 · Gnu+3 · Gnu C Library+3

Stefan Cornelius

·

Publicado

2012-07-18

·

Atualizado

2019-04-22

·

CVE-2012-3405

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GNU C Library (aka glibc) versions 2.14 and other versions
Description The issue arises from a miscalculation of buffer length in the vfprintf function, allowing attackers to bypass format-string protection and cause a denial of service, resulting in a segmentation fault and crash. This occurs when a format string contains a large number of format specifiers, triggering desynchronization within the buffer size handling.
Recommendations For GNU C Library (aka glibc) versions 2.14 and other versions, consider disabling the vfprintf function as a temporary workaround until a patch is available. Restrict the use of format strings with multiple format specifiers to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_1098
CVE-2012-3405
DLA-165-1
DSA-3169-1
RHSA-2012:1098
RHSA-2012:1200
RHSA-2012_1098
SUSE-SU-2015:0551-1

Produtos afetados

Centos
Gnu C Library
Red Hat
Suse