Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-develUpgrade glibc-utilsUpgrade glibc-commonUpgrade glibc-headersUpgrade nscdUpgrade glibc-staticUpgrade glibc | Dec 1, 2016 | May 2, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | May 2, 2013 |
| Oracle_linux | — | Upgrade glibc-commonUpgrade nscdUpgrade glibc-staticUpgrade glibc-utilsUpgrade glibc-headersUpgrade glibcUpgrade glibc-devel | Oct 16, 2024 | May 2, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 17, 2010 |
| Suse | — | Upgrade glibc-localeUpgrade glibc-x86Upgrade glibc-devel-32bitUpgrade glibcUpgrade glibc-32bitUpgrade glibc-profile-x86Upgrade glibc-htmlUpgrade glibc-locale-x86Upgrade glibc-i18ndataUpgrade glibc-develUpgrade glibc-profileUpgrade nscdUpgrade glibc-profile-32bitUpgrade glibc-locale-32bitUpgrade glibc-info | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libc6Upgrade libc-bin | Nov 8, 2024 | May 2, 2013 |
| Vmsa 2012 0013 | — | Upgrade VMware ESX 4.1 to build number 800380 | Sep 17, 2012 | Sep 17, 2012 |
| Vmsa 2012 0018 | — | Upgrade VMware ESXi 5.0 to build number 912577Upgrade VMware ESXi 5.1 to build number 911593 | Jan 4, 2013 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub