CVE-2012-0864

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
gnuglibc
2.14
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
oneiric
Fixed 2.13-20ubuntu5.1
released
natty
Fixed 2.13-0ubuntu13.1
released
maverick
Fixed 2.12.1-0ubuntu10.4
released
lucid
Fixed 2.11.1-0ubuntu7.10
released
hardy
dne
glibc
oneiric
dne
natty
dne
maverick
dne
lucid
dne
hardy
Fixed 2.7-10ubuntu8.1
released
Common Weakness Enumeration