Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nscdUpgrade glibc-headersUpgrade glibc-staticUpgrade glibcUpgrade glibc-utilsUpgrade glibc-develUpgrade glibc-common | Dec 1, 2016 | May 2, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | May 2, 2013 |
| Oracle_linux | — | Upgrade glibc-staticUpgrade glibc-commonUpgrade glibc-utilsUpgrade nscdUpgrade glibc-headersUpgrade glibcUpgrade glibc-devel | Oct 16, 2024 | May 2, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 17, 2010 |
| Suse | — | Upgrade glibc-htmlUpgrade glibc-32bitUpgrade glibc-profile-x86Upgrade glibc-x86Upgrade glibc-locale-x86Upgrade glibcUpgrade glibc-i18ndataUpgrade glibc-devel-32bitUpgrade glibc-localeUpgrade glibc-develUpgrade glibc-infoUpgrade glibc-profile-32bitUpgrade glibc-profileUpgrade nscdUpgrade glibc-locale-32bit | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libc6Upgrade libc-bin | Nov 8, 2024 | May 2, 2013 |
| Vmsa 2012 0013 | — | Upgrade VMware ESX 4.1 to build number 800380 | Sep 17, 2012 | Sep 17, 2012 |
| Vmsa 2012 0018 | — | Upgrade VMware ESXi 5.0 to build number 912577Upgrade VMware ESXi 5.1 to build number 911593 | Jan 4, 2013 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub