Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nscdUpgrade glibc-staticUpgrade glibc-headersUpgrade glibcUpgrade glibc-develUpgrade glibc-utilsUpgrade glibc-common | Dec 1, 2016 | May 2, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | May 2, 2013 |
| Oracle_linux | — | Upgrade glibc-develUpgrade glibc-headersUpgrade glibcUpgrade glibc-staticUpgrade glibc-commonUpgrade glibc-utilsUpgrade nscd | Oct 16, 2024 | May 2, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 17, 2010 |
| Suse | — | Upgrade glibc-dceext-64bitUpgrade glibc-dceextUpgrade glibc-locale-32bitUpgrade glibc-devel-64bitUpgrade nscdUpgrade glibc-profileUpgrade glibc-profile-32bitUpgrade glibc-infoUpgrade glibc-64bitUpgrade glibc-dceext-x86Upgrade glibc-locale-x86Upgrade glibc-dceext-32bitUpgrade glibc-i18ndataUpgrade glibc-htmlUpgrade glibcUpgrade glibc-x86Upgrade glibc-32bitUpgrade glibc-profile-64bitUpgrade glibc-devel-32bitUpgrade glibc-locale-64bitUpgrade glibc-localeUpgrade glibc-develUpgrade glibc-profile-x86 | Dec 12, 2013 | May 2, 2013 |
| Ubuntu | — | Upgrade libc-binUpgrade libc6 | Nov 8, 2024 | May 2, 2013 |
| Vmsa 2012 0013 | — | Upgrade VMware ESX 4.1 to build number 800380 | Sep 17, 2012 | Sep 17, 2012 |
| Vmsa 2012 0018 | — | Upgrade VMware ESXi 5.1 to build number 911593Upgrade VMware ESXi 5.0 to build number 912577 | Jan 4, 2013 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub