CVE-2012-3480
published 2012-08-25CVE-2012-3480: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka…
PriorityP425medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EXPLOIT
EPSS
0.99%
59.0th percentile
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.13-36 (bookworm) | glibc 2.13-36 (bookworm) |
| gnu | glibc | — | — |
| gnu | glibc | >= 0 < 2.13-36 | 2.13-36 |
| gnu | glibc | >= 0 < 2.13-36 | 2.13-36 |
| gnu | glibc | >= 0 < 2.13-36 | 2.13-36 |
| gnu | glibc | >= 0 < 2.13-36 | 2.13-36 |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware security updates for vCSA, vCenter Server, and ESXi
vendor_vmware·2012-12-20·CVSS 4.0
CVE-2009-5029 [MEDIUM] VMware security updates for vCSA, vCenter Server, and ESXi
VMSA-2012-0018: VMware security updates for vCSA, vCenter Server, and ESXi
a. vCenter Server Appliance directory traversal The vCenter Server Appliance (vCSA) contains a directory traversal vulnerability that allows an authenticated remote user to retrieve arbitrary files. Exploitation of this issue may expose sensitive information stored on the server. VMware would like to thank Alexander Minozhenko from ERPScan for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-6324 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCSA Product Vers
Ubuntu
GNU C Library regression
vendor_ubuntu·2012-12-17·CVSS 5.0
CVE-2012-3480 [MEDIUM] GNU C Library regression
Title: GNU C Library regression
Summary: USN-1589-1 exposed a regression in the GNU C Library floating point parser.
USN-1589-1 fixed vulnerabilities in the GNU C Library. One of the updates
exposed a regression in the floating point parser. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that positional arguments to the printf() family
of functions were not handled properly in the GNU C Library. An
attacker could possibly use this to cause a stack-based buffer
overflow, creating a denial of service or possibly execute arbitrary
code. (CVE-2012-3404, CVE-2012-3405, CVE-2012-3406)
It was discovered that multiple integer overflows existed in the
strtod(), strtof() and strtold() functions in the GNU C Library. An
attacker c
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2012-10-02·CVSS 5.0
CVE-2012-3404 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Multiple security issues were fixed in the GNU C Library.
It was discovered that positional arguments to the printf() family
of functions were not handled properly in the GNU C Library. An
attacker could possibly use this to cause a stack-based buffer
overflow, creating a denial of service or possibly execute arbitrary
code. (CVE-2012-3404, CVE-2012-3405, CVE-2012-3406)
It was discovered that multiple integer overflows existed in the
strtod(), strtof() and strtold() functions in the GNU C Library. An
attacker could possibly use this to trigger a stack-based buffer
overflow, creating a denial of service or possibly execute arbitrary
code. (CVE-2012-3480)
Instructions: After a standard system update you need to reboot your computer to make
al
Red Hat
glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routines
vendor_redhat·2012-08-12·CVSS 4.6
CVE-2012-3480 [MEDIUM] CWE-190 glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routines
glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routines
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Debian
CVE-2012-3480: glibc - Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strto...
vendor_debian·2012·CVSS 4.6
CVE-2012-3480 [MEDIUM] CVE-2012-3480: glibc - Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strto...
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.13-36)
bullseye: resolved (fixed in 2.13-36)
forky: resolved (fixed in 2.13-36)
sid: resolved (fixed in 2.13-36)
trixie: resolved (fixed in 2.13-36)
GHSA
GHSA-mch7-w8fj-4pc4: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Libr
ghsa_unreviewed·2022-05-17
CVE-2012-3480 [MEDIUM] GHSA-mch7-w8fj-4pc4: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Libr
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
OSV
CVE-2012-3480: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Libr
osv·2012-08-25·CVSS 4.6
CVE-2012-3480 [MEDIUM] CVE-2012-3480: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Libr
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
No detection rules found.
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085190.htmlhttp://osvdb.org/84710http://rhn.redhat.com/errata/RHSA-2012-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1262.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1325.htmlhttp://secunia.com/advisories/50201http://secunia.com/advisories/50422http://sourceware.org/bugzilla/show_bug.cgi?id=14459http://sourceware.org/ml/libc-alpha/2012-08/msg00202.htmlhttp://www.openwall.com/lists/oss-security/2012/08/13/4http://www.openwall.com/lists/oss-security/2012/08/13/6http://www.securityfocus.com/bid/54982http://www.securitytracker.com/id?1027374http://www.ubuntu.com/usn/USN-1589-1https://security.gentoo.org/glsa/201503-04http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085190.htmlhttp://osvdb.org/84710http://rhn.redhat.com/errata/RHSA-2012-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1262.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1325.htmlhttp://secunia.com/advisories/50201http://secunia.com/advisories/50422http://sourceware.org/bugzilla/show_bug.cgi?id=14459http://sourceware.org/ml/libc-alpha/2012-08/msg00202.htmlhttp://www.openwall.com/lists/oss-security/2012/08/13/4http://www.openwall.com/lists/oss-security/2012/08/13/6http://www.securityfocus.com/bid/54982http://www.securitytracker.com/id?1027374http://www.ubuntu.com/usn/USN-1589-1https://security.gentoo.org/glsa/201503-04
2012-08-25
Published