LWN.net Logo

glibc: format string protection mechanism bypass

Package(s):glibc CVE #(s):CVE-2012-0864
Created:February 27, 2012 Updated:March 22, 2012
Description: From the Red Hat bugzilla:

In the Phrack article "A Eulogy for Format Strings", a researcher using nickname "Captain Planet" reported an integer overflow flaw in the format string protection mechanism offered by FORTIFY_SOURCE. A remote attacker could provide a specially crafted executable, leading to FORTIFY_SOURCE format string protection mechanism bypass, when executed.

Alerts:
Fedora FEDORA-2012-2162 2012-02-25
Fedora FEDORA-2012-2144 2012-03-08
Ubuntu USN-1396-1 2012-03-09
Red Hat RHSA-2012:0393-01 2012-03-15
CentOS CESA-2012:0393 2012-03-15
Oracle ELSA-2012-0393 2012-03-15
Red Hat RHSA-2012:0397-01 2012-03-19
CentOS CESA-2012:0397 2012-03-20
Oracle ELSA-2012-0397 2012-03-20
Scientific Linux SL-glib-20120321 2012-03-21
Scientific Linux SL-glib-20120321 2012-03-21
Mandriva MDVSA-2013:162 2013-05-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds