REDHAT-BUG-524671: Integer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1391 to the following vulnerability:
Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GETNUMBER macro; and (2) the printf function, related to leftprec and rightprec.
References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1391 https://bugzilla.novell.com/showbug.cgi?id=375315 http://www.securityfocus.com/bid/36443/references http://securityreason.com/achievementsecurityalert/67
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-524671?
REDHAT-BUG-524671 has been classified with a high severity due to multiple integer overflows that can lead to potential security risks.
How do I fix REDHAT-BUG-524671?
To fix REDHAT-BUG-524671, you should upgrade your affected systems to the latest versions of NetBSD, FreeBSD, or Mac OS that contain the security patches.
Which systems are affected by REDHAT-BUG-524671?
The affected systems by REDHAT-BUG-524671 include NetBSD 4.x, FreeBSD 6.x, FreeBSD 7.x, and potentially other BSD and Apple Mac OS versions.
What type of vulnerability is REDHAT-BUG-524671?
REDHAT-BUG-524671 is an integer overflow vulnerability affecting libc on various BSD and Apple Mac OS platforms.
When was REDHAT-BUG-524671 reported?
REDHAT-BUG-524671 was reported in relation to the CVE-2008-1391 identifier, indicating that it has been a known issue since 2008.