PT-2008-6880 · Gnu+2 · Glibc-Source+45

Maksymilian Arciemowicz

·

Published

1970-01-01

·

Updated

2018-10-11

·

CVE-2008-1391

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libc6 versions (affected versions not specified) glibc-source versions (affected versions not specified) libc6-i386 versions (affected versions not specified) libc6-sparcv9b versions (affected versions not specified) libc6-udeb versions (affected versions not specified) libc6-mipsn32 versions (affected versions not specified) glibc-obsolete versions (affected versions not specified) libc6.1-dbg versions (affected versions not specified) glibc-doc versions (affected versions not specified) libnss-dns-udeb versions (affected versions not specified) libc6-dev-sparc64 versions (affected versions not specified) libc6.1-prof versions (affected versions not specified) libc6-xen versions (affected versions not specified) libc6-dev-mips64 versions (affected versions not specified) libc6.1-dev versions (affected versions not specified) locales-all versions (affected versions not specified) libc6-pic versions (affected versions not specified) libc6.1-pic versions (affected versions not specified) libc6-i686 versions (affected versions not specified) nscd versions (affected versions not specified) glibc-dceext-32bit versions (affected versions not specified) glibc-64bit versions (affected versions not specified) libc6-prof versions (affected versions not specified) libnss-files-udeb versions (affected versions not specified) libc6-amd64 versions (affected versions not specified) locales versions (affected versions not specified) libc6.1-udeb versions (affected versions not specified) libc6-sparc64 versions (affected versions not specified) glibc-debuginfo versions (affected versions not specified) glibc-devel-64bit versions (affected versions not specified) libc6.1 versions (affected versions not specified) libc6-dev-s390x versions (affected versions not specified) libc6-dev versions (affected versions not specified) glibc-profile-64bit versions (affected versions not specified) libc6-dev-mipsn32 versions (affected versions not specified) libc6-dev-ppc64 versions (affected versions not specified) libc6-mips64 versions (affected versions not specified) glibc-locale-64bit versions (affected versions not specified) libc6-s390x versions (affected versions not specified) glibc-dceext versions (affected versions not specified) libc6-ppc64 versions (affected versions not specified) libc6.1-alphaev67 versions (affected versions not specified) libc6-dbg versions (affected versions not specified) libc6-dev-amd64 versions (affected versions not specified)
Description The issue involves multiple vulnerabilities in various packages of the Debian GNU/Linux and SUSE Linux Enterprise operating systems. These vulnerabilities can lead to breaches of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely. In some cases, the vulnerabilities are related to integer overflows in the strfmon function and the printf function, which can allow context-dependent attackers to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01134
BDU:2015-01135
BDU:2015-01136
BDU:2015-01137
BDU:2015-01138
BDU:2015-01139
BDU:2015-01140
BDU:2015-01141
BDU:2015-01142
BDU:2015-01143
BDU:2015-01144
BDU:2015-01145
BDU:2015-01146
BDU:2015-01147
BDU:2015-01148
BDU:2015-01149
BDU:2015-01150
BDU:2015-01151
BDU:2015-01152
BDU:2015-01153
BDU:2015-01154
BDU:2015-01155
BDU:2015-01156
BDU:2015-01157
BDU:2015-01158
BDU:2015-01159
BDU:2015-01160
BDU:2015-01161
BDU:2015-01162
BDU:2015-01163
BDU:2015-01164
BDU:2015-01165
BDU:2015-01166
BDU:2015-01167
BDU:2015-01168
BDU:2015-01169
BDU:2015-01170
BDU:2015-04440
BDU:2015-04441
BDU:2015-04442
BDU:2015-04443
BDU:2015-04444
BDU:2015-04445
BDU:2015-04446
BDU:2015-04447
CVE-2008-1391
DSA-2058-1

Affected Products

Debian
Suse Linux Enterprise
Glibc-64Bit
Glibc-Dceext
Glibc-Dceext-32Bit
Glibc-Debuginfo
Glibc-Devel-64Bit
Glibc-Doc
Glibc-Locale-64Bit
Glibc-Obsolete
Glibc-Profile-64Bit
Glibc-Source
Libc6
Libc6-Amd64
Libc6-Dbg
Libc6-Dev
Libc6-Dev-Amd64
Libc6-Dev-Mips64
Libc6-Dev-Mipsn32
Libc6-Dev-Ppc64
Libc6-Dev-S390X
Libc6-Dev-Sparc64
Libc6-I386
Libc6-I686
Libc6-Mips64
Libc6-Mipsn32
Libc6-Pic
Libc6-Ppc64
Libc6-Prof
Libc6-S390X
Libc6-Sparc64
Libc6-Sparcv9
Libc6-Udeb
Libc6-Xen
Libc6.1
Libc6.1-Alphaev67
Libc6.1-Dbg
Libc6.1-Dev
Libc6.1-Pic
Libc6.1-Prof
Libc6.1-Udeb
Libnss-Dns-Udeb
Libnss-Files-Udeb
Locales
Locales-All
Nscd