The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses positional parameters and many format specifiers.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-commonUpgrade glibc-develUpgrade glibc-headersUpgrade glibc-staticUpgrade glibc-utilsUpgrade nscdUpgrade glibc | Dec 1, 2016 | Feb 10, 2014 |
| Debian | — | Upgrade glibc | Jul 30, 2024 | Feb 10, 2014 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Feb 10, 2014 |
| Oracle_linux | — | Upgrade glibc-utilsUpgrade glibcUpgrade glibc-develUpgrade glibc-staticUpgrade glibc-commonUpgrade glibc-headersUpgrade nscd | Oct 16, 2024 | Feb 10, 2014 |
| Suse | — | Upgrade glibc-localeUpgrade glibc-htmlUpgrade nscdUpgrade glibc-locale-32bitUpgrade glibcUpgrade glibc-profile-32bitUpgrade glibc-x86Upgrade glibc-i18ndataUpgrade glibc-locale-x86Upgrade glibc-profileUpgrade glibc-infoUpgrade glibc-devel-32bitUpgrade glibc-32bitUpgrade glibc-profile-x86Upgrade glibc-devel | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Feb 10, 2014 |
| Vmsa 2012 0018 | — | Upgrade VMware ESXi 5.1 to build number 911593Upgrade VMware ESXi 5.0 to build number 912577 | Jan 4, 2013 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub