Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
NameCVE-2009-4881First vendor Publication2010-06-01
VendorCveLast vendor Modification2011-01-12

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4881

CWE : Common Weakness Enumeration

idName
CWE-189Numeric Errors (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application46

OpenVAS Exploits

DateDescription
2011-03-09Name : Gentoo Security Advisory GLSA 201011-01 (glibc)
File : nvt/glsa_201011_01.nasl
2010-06-11Name : Mandriva Update for glibc MDVSA-2010:111 (glibc)
File : nvt/gb_mandriva_MDVSA_2010_111.nasl
2010-06-10Name : Debian Security Advisory DSA 2058-1 (glibc, eglibc)
File : nvt/deb_2058_1.nasl
2010-04-06Name : Mandriva Update for initscripts MDVA-2010:111 (initscripts)
File : nvt/gb_mandriva_MDVA_2010_111.nasl

Open Source Vulnerability Database (OSVDB)

idDescription
65079GNU C Library stdlib/strfmon_l.c __vstrfmon_l Function Format String Overflow...

Nessus® Vulnerability Scanner

DateDescription
2010-11-16Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201011-01.nasl - Type : ACT_GATHER_INFO
2010-06-11Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2058.nasl - Type : ACT_GATHER_INFO
2010-06-09Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2010-111.nasl - Type : ACT_GATHER_INFO

Internal Sources (Detail)

SourceUrl
CONFIRMhttp://sources.redhat.com/bugzilla/show_bug.cgi?id=10600
http://sourceware.org/git/?p=glibc.git;a=commit;h=153aa31b93be22e01b236375fb0...
DEBIANhttp://www.debian.org/security/2010/dsa-2058
GENTOOhttp://security.gentoo.org/glsa/glsa-201011-01.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:111
XFhttp://xforce.iss.net/xforce/xfdb/59241

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2014-02-17 10:52:55
  • Multiple Updates
2013-05-11 00:04:42
  • Multiple Updates