The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number of format specifiers that triggers "desynchronization within the buffer size handling," a different vulnerability than CVE-2012-3404.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibcUpgrade glibc-headersUpgrade glibc-develUpgrade glibc-staticUpgrade glibc-commonUpgrade nscdUpgrade glibc-utils | Dec 1, 2016 | Feb 10, 2014 |
| Debian | — | Upgrade glibc | Jul 30, 2024 | Feb 10, 2014 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Feb 10, 2014 |
| Oracle_linux | — | Upgrade glibc-utilsUpgrade glibc-staticUpgrade glibc-develUpgrade glibcUpgrade glibc-headersUpgrade nscdUpgrade glibc-common | Oct 16, 2024 | Feb 10, 2014 |
| Suse | — | Upgrade glibcUpgrade glibc-i18ndataUpgrade glibc-profile-x86Upgrade glibc-profileUpgrade glibc-locale-x86Upgrade glibc-localeUpgrade glibc-develUpgrade glibc-locale-32bitUpgrade glibc-devel-32bitUpgrade glibc-profile-32bitUpgrade glibc-htmlUpgrade glibc-infoUpgrade glibc-32bitUpgrade glibc-x86Upgrade nscd | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Feb 10, 2014 |
| Vmsa 2012 0018 | — | Upgrade VMware ESXi 5.0 to build number 912577Upgrade VMware ESXi 5.1 to build number 911593 | Jan 4, 2013 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub