Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4880

Опубликовано: 01 июн. 2010
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5

Описание

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.12-0ubuntu2
hardy

DNE

jaunty

DNE

karmic

released

2.10.1-0ubuntu17
lucid

released

2.11.1-0ubuntu7.1
upstream

released

2.12

Показывать по

РелизСтатусПримечание
dapper

released

2.3.6-0ubuntu20.6
devel

DNE

hardy

released

2.7-10ubuntu6
jaunty

released

2.9-4ubuntu6.2
karmic

DNE

lucid

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 94%
0.13534
Средний

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

nvd
около 15 лет назад

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

debian
около 15 лет назад

Multiple integer overflows in the strfmon implementation in the GNU C ...

github
около 3 лет назад

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 94%
0.13534
Средний

5 Medium

CVSS2