CVE-2009-4881
published 2010-06-01CVE-2009-4881: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.02%
79.0th percentile
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.11.1-1 (bookworm) | glibc 2.11.1-1 (bookworm) |
| gnu | glibc | <= 2.9 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4g7-ccjm-h2xx: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2009-4881 [HIGH] GHSA-q4g7-ccjm-h2xx: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
OSV
CVE-2009-4881: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l
osv·2010-06-01·CVSS 7.5
CVE-2009-4881 [HIGH] CVE-2009-4881: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
Red Hat
kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
vendor_redhat·2009-10-08·CVSS 4.9
CVE-2009-3612 [MEDIUM] kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
Statement: This issue is not planned to be fixed in Red Hat Enterprise Linux 3 due to this product being in Production 3 of its maintenance life-cycle, where only qualified security errata of important or critical impact are addressed.
For further information about the Errata Support Policy, visit: https://access.redhat.com/support/policy/updates/errata/
Debian
CVE-2009-4881: glibc - Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfm...
vendor_debian·2009·CVSS 7.5
CVE-2009-4881 [HIGH] CVE-2009-4881: glibc - Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfm...
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
Scope: local
bookworm: resolved (fixed in 2.11.1-1)
bullseye: resolved (fixed in 2.11.1-1)
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved (fixed in 2.11.1-1)
Red Hat
(32-bit): Integer overflow in the __vstrfmon_l function
vendor_redhat·2008-03-25·CVSS 7.5
CVE-2009-4881 [HIGH] CWE-190 (32-bit): Integer overflow in the __vstrfmon_l function
(32-bit): Integer overflow in the __vstrfmon_l function
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
Statement: Red Hat does not consider this bug to be a security issue. Properly written application should not use arbitrary untrusted data as part of the format string passed to functions as strfmon or printf family functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-4881 glibc (32-bit): Integer overflow in the __vstrfmon_l function
bugzilla·2010-06-02·CVSS 7.5
CVE-2009-4881 [HIGH] CVE-2009-4881 glibc (32-bit): Integer overflow in the __vstrfmon_l function
CVE-2009-4881 glibc (32-bit): Integer overflow in the __vstrfmon_l function
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4881 to
the following vulnerability:
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in
the strfmon implementation in the GNU C Library (aka glibc or libc6)
before 2.10.1 allows context-dependent attackers to cause a denial of
service (application crash) via a crafted format string, as
demonstrated by the %99999999999999999999n string, a related issue to
CVE-2008-1391.
References:
[1] http://sources.redhat.com/bugzilla/show_bug.cgi?id=10600
[2] http://sourceware.org/git/?p=glibc.git;a=commit;h=153aa31b93be22e01b236375fb02a9f9b9a0195f
[3] http://sources.redhat.com/bugzilla/show_bug.cgi?id=10600
[4] http://securityreason.com/a
Bugzilla
CVE-2008-1391 glibc: strfmon format string problem
bugzilla·2009-09-21·CVSS 7.5
CVE-2008-1391 [HIGH] CVE-2008-1391 glibc: strfmon format string problem
CVE-2008-1391 glibc: strfmon format string problem
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1391 to
the following vulnerability:
Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391
https://bugzilla.novell.com/show_bug.cgi?id=375315
http://www.securityfocus.com/bid/36443/references
http://securityreason.com/achievement_securityalert/67
Discus
http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sources.redhat.com/bugzilla/show_bug.cgi?id=10600http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=153aa31b93be22e01b236375fb02a9f9b9a0195fhttp://www.debian.org/security/2010/dsa-2058http://www.mandriva.com/security/advisories?name=MDVSA-2010:111https://exchange.xforce.ibmcloud.com/vulnerabilities/59241http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sources.redhat.com/bugzilla/show_bug.cgi?id=10600http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=153aa31b93be22e01b236375fb02a9f9b9a0195fhttp://www.debian.org/security/2010/dsa-2058http://www.mandriva.com/security/advisories?name=MDVSA-2010:111https://exchange.xforce.ibmcloud.com/vulnerabilities/59241
2010-06-01
Published