CVE-2008-1391
BSD (Multiple Distributions) - 'strfmon()' Integer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
Múltiples desbordamientos de entero en libc de NetBSD 4.x, FreeBSD 6.x y 7.x, y posiblemente otras plataformas BSD y Apple Mac OS permiten a atacantes dependientes del contexto ejecutar código de su elección a través de valores de ciertos campos de enteros en el argumento de formato de (1) la función strfmon en lib/libc/stdlib/strfmon.c, en relación a la macro GET_NUMBER; y (2) la función printf, en relación a left_prec y right_prec.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-03-18 CVE Reserved
- 2008-03-27 CVE Published
- 2008-03-27 First Exploit
- 2024-08-07 CVE Updated
- 2024-11-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-189: Numeric Errors
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/stdlib/strfmon.c | X_refsource_confirm | |
http://secunia.com/advisories/29574 | Third Party Advisory | |
http://secunia.com/advisories/33179 | Third Party Advisory | |
http://support.apple.com/kb/HT3338 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/490158/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/28479 | Vdb Entry | |
http://www.securitytracker.com/id?1019722 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA08-350A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/3444 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41504 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31550 | 2008-03-27 | |
http://securityreason.com/achievement_securityalert/53 | 2024-08-07 | |
http://securityreason.com/securityalert/3770 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 6.0 Search vendor "Freebsd" for product "Freebsd" and version "6.0" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 6.0 Search vendor "Freebsd" for product "Freebsd" and version "6.0" | release |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 6.0 Search vendor "Freebsd" for product "Freebsd" and version "6.0" | stable |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 6.0_p5_release Search vendor "Freebsd" for product "Freebsd" and version "6.0_p5_release" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.0 Search vendor "Freebsd" for product "Freebsd" and version "7.0" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.0 Search vendor "Freebsd" for product "Freebsd" and version "7.0" | pre-release |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.0_beta4 Search vendor "Freebsd" for product "Freebsd" and version "7.0_beta4" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.0_releng Search vendor "Freebsd" for product "Freebsd" and version "7.0_releng" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 4.0 Search vendor "Netbsd" for product "Netbsd" and version "4.0" | - |
Affected
|