PT-2013-1211 · Gnu+3 · Glibc+3

Captain Planet

+1

·

Published

2012-03-15

·

Updated

2023-02-13

·

CVE-2012-0864

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.15-r3
Description The issue concerns multiple vulnerabilities in the glibc package, which can lead to breaches of confidentiality, integrity, and availability of protected information. Exploitation can occur locally. Specifically, an integer overflow in the vfprintf function allows attackers to bypass the FORTIFY SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
Recommendations For glibc versions prior to 2.15-r3, update to version 2.15-r3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vfprintf function until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-09685
CESA-2012_0393
CVE-2012-0864
RHSA-2012:0393
RHSA-2012:0397
RHSA-2012:0531
RHSA-2012_0393
RHSA-2012_0397

Affected Products

Centos
Red Hat
Suse
Glibc