CVE-2012-0864

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
gnuglibc
2.14
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
hardy
dne
lucid
Fixed 2.11.1-0ubuntu7.10
released
maverick
Fixed 2.12.1-0ubuntu10.4
released
natty
Fixed 2.13-0ubuntu13.1
released
oneiric
Fixed 2.13-20ubuntu5.1
released
glibc
hardy
Fixed 2.7-10ubuntu8.1
released
lucid
dne
maverick
dne
natty
dne
oneiric
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
glibc
RHEL 6
0:2.12-1.47.el6_2.9
fixed
glibc-common
RHEL 6
0:2.12-1.47.el6_2.9
fixed
glibc-devel
RHEL 6
0:2.12-1.47.el6_2.9
fixed
glibc-headers
RHEL 6
0:2.12-1.47.el6_2.9
fixed
glibc-static
RHEL 6
0:2.12-1.47.el6_2.9
fixed
glibc-utils
RHEL 6
0:2.12-1.47.el6_2.9
fixed
nscd
RHEL 6
0:2.12-1.47.el6_2.9
fixed
Common Weakness Enumeration