PT-2014-2265 · Gnu+3 · Glibc+3

Stefan Cornelius

·

Published

2012-07-18

·

Updated

2019-04-22

·

CVE-2012-3404

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions glibc version 2.12
Description The issue is related to the vfprintf function in the GNU C Library, which does not properly calculate a buffer length. This allows attackers to bypass the FORTIFY SOURCE format-string protection mechanism, potentially causing a denial of service due to stack corruption and crash. The attack is context-dependent and involves the use of a format string with positional parameters and many format specifiers.
Recommendations For glibc version 2.12, consider applying a patch or updating to a newer version that addresses this issue, as the current version does not properly handle buffer length calculations in the vfprintf function.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_1098
CVE-2012-3404
DSA-3169-1
RHSA-2012:1098
RHSA-2012:1200
RHSA-2012_1098
SUSE-SU-2012_1666-1
SUSE-SU-2015:0551-1

Affected Products

Centos
Red Hat
Suse
Glibc