CVE-2009-4881 PUBLISHED CVSS 5 MEDIUM

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.

EPSS 0.60% · 69.4th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
0.60%
69.4th percentile

Affected Products

VendorProductVersions
n/an/an/a
gnuglibc0, 1.00, 1.01

Timeline

References

Open in Interactive Console →