cbcvebase.
CVE-2012-3480
published 2012-08-25

CVE-2012-3480: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka…

medium4.6CVSS 3.1
AVLACLAuNCPIPAP
EXPLOIT
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.13-36 (bookworm)glibc 2.13-36 (bookworm)
gnuglibc
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
vmwarevcenter_server
vmwarevmware_esxi
vmwarevsphere

CVSS provenance

nvd4.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM