VDB
CVE-2009-4881
CVE-2009-4881
PUBLISHED
CVSS 5 MEDIUM
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
EPSS 0.60% · 70.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.60%
70.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| gnu | glibc | 0, 1.00, 1.01 |
Exploit Intelligence
Timeline
- Jun 1, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- MDVSA-2010:111 vendor-advisory
- GLSA-201011-01 vendor-advisory
- http://sources.redhat.com/bugzilla/show_bug.cgi?id=10600 url
- gnuclibrary-vstrfmonl-overflow(59241) vdb
- http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=153aa31b93be22e01b236375fb02a9f9b9a0195f url
- DSA-2058 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-4881 advisory
- http://sourceware.org/git/?p=glibc.git;a=commit;h=153aa31b93be22e01b236375fb02a9f9b9a0195f url