CVE-2009-4880 PUBLISHED CVSS 5 MEDIUM

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

EPSS 12.96% · 94.0th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
12.96%
94.0th percentile

Affected Products

VendorProductVersions
gnuglibc2.10, 0, 2.0
n/an/an/a

Timeline

References

Open in Interactive Console →