VDB
CVE-2012-2674
CVE-2012-2674
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple integer overflows in the (1) chk_malloc, (2) leak_malloc, and (3) leak_memalign functions in libc/bionic/malloc_debug_leak.c in Bionic (libc) for Android, when libc.debug.malloc is set, make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.
EPSS 0.79% · 54.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.79%
54.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bionic | ||
| n/a | n/a | n/a |
Timeline
- Jul 25, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2012-2674 advisory
- http://kqueue.org/blog/2012/03/05/memory-allocator-security-revisited url
- http://www.openwall.com/lists/oss-security/2012/06/05/1 url
- http://kqueue.org/blog/2012/03/05/memory-allocator-security-revisited/ technical
- http://www.openwall.com/lists/oss-security/2012/06/07/13 technical
- https://github.com/android/platform_bionic/commit/7f5aa4f35e23fd37425b3a5041737cdf58f87385 exploit