CVE-2008-1391: Integer Overflow

Published Mar 25, 2008
·
Updated

Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1391 to the following vulnerability:

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GETNUMBER macro; and (2) the printf function, related to leftprec and rightprec.

References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391 https://bugzilla.novell.com/showbug.cgi?id=375315 http://www.securityfocus.com/bid/36443/references http://securityreason.com/achievementsecurityalert/67

Affected Software

9 affected components
FreeBSD FreeBSD=7.0-pre-release
NetBSD NetBSD=4.0
FreeBSD FreeBSD=7.0_beta4
FreeBSD FreeBSD=7.0
FreeBSD FreeBSD=6.0_p5_release
FreeBSD FreeBSD=6.0
FreeBSD FreeBSD=7.0_releng
FreeBSD FreeBSD=6.0-release
FreeBSD FreeBSD=6.0-stable

Event History

Mar 25, 2008
CVE Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionSeverity
Mar 27, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Sep 21, 2009
Data Sourced
via Red Hat·04:59 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2008-1391?

CVE-2008-1391 has been classified as a high severity vulnerability due to the potential for integer overflows leading to various security risks.

2

How do I fix CVE-2008-1391?

To address CVE-2008-1391, update to the latest patched versions of FreeBSD or NetBSD that resolve the integer overflow issue.

3

Which software is affected by CVE-2008-1391?

CVE-2008-1391 affects multiple versions of FreeBSD 6.x, 7.x, and NetBSD 4.x.

4

What type of vulnerability is CVE-2008-1391?

CVE-2008-1391 is classified as an integer overflow vulnerability which can lead to memory corruption.

5

Can CVE-2008-1391 be exploited remotely?

Yes, CVE-2008-1391 allows remote attackers to exploit vulnerable systems, potentially executing arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203