LWN.net Logo

glibc: denial of service

Package(s):glibc CVE #(s):CVE-2009-4880 CVE-2009-4881
Created:June 10, 2010 Updated:November 23, 2010
Description:

From the Debian advisory:

Maksymilian Arciemowicz discovered that the GNU C library did not correctly handle integer overflows in the strfmon family of functions. If a user or automated system were tricked into processing a specially crafted format string, a remote attacker could crash applications, leading to a denial of service.

Alerts:
Gentoo 201011-01 2010-11-15
Debian DSA-2058-1 2010-06-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds