First published: Mon Sep 21 2009(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2008-1391">CVE-2008-1391</a> to the following vulnerability: Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec. References: ----------- <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391</a> <a href="https://bugzilla.novell.com/show_bug.cgi?id=375315">https://bugzilla.novell.com/show_bug.cgi?id=375315</a> <a href="http://www.securityfocus.com/bid/36443/references">http://www.securityfocus.com/bid/36443/references</a> <a href="http://securityreason.com/achievement_securityalert/67">http://securityreason.com/achievement_securityalert/67</a>
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD current | >=4.x | |
FreeBSD Kernel | >=6.x>=7.x | |
Apple iOS and macOS | >= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-524671 has been classified with a high severity due to multiple integer overflows that can lead to potential security risks.
To fix REDHAT-BUG-524671, you should upgrade your affected systems to the latest versions of NetBSD, FreeBSD, or Mac OS that contain the security patches.
The affected systems by REDHAT-BUG-524671 include NetBSD 4.x, FreeBSD 6.x, FreeBSD 7.x, and potentially other BSD and Apple Mac OS versions.
REDHAT-BUG-524671 is an integer overflow vulnerability affecting libc on various BSD and Apple Mac OS platforms.
REDHAT-BUG-524671 was reported in relation to the CVE-2008-1391 identifier, indicating that it has been a known issue since 2008.