First published: Tue Mar 25 2008(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2008-1391">CVE-2008-1391</a> to the following vulnerability: Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec. References: ----------- <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391</a> <a href="https://bugzilla.novell.com/show_bug.cgi?id=375315">https://bugzilla.novell.com/show_bug.cgi?id=375315</a> <a href="http://www.securityfocus.com/bid/36443/references">http://www.securityfocus.com/bid/36443/references</a> <a href="http://securityreason.com/achievement_securityalert/67">http://securityreason.com/achievement_securityalert/67</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =6.0 | |
FreeBSD FreeBSD | =6.0-release | |
FreeBSD FreeBSD | =6.0-stable | |
FreeBSD FreeBSD | =6.0_p5_release | |
FreeBSD FreeBSD | =7.0 | |
FreeBSD FreeBSD | =7.0-pre-release | |
FreeBSD FreeBSD | =7.0_beta4 | |
FreeBSD FreeBSD | =7.0_releng | |
NetBSD NetBSD | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.