CVE-2008-1391

NetBSD 4.x-FreeBSD 6.x-7.x - RCE

Title source: llm

Description

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · cdosbsd
https://www.exploit-db.com/exploits/31550

Scores

EPSS 0.1906
EPSS Percentile 95.4%

Details

CWE
CWE-189
Status published
Products (6)
freebsd/freebsd 6.0 (3 CPE variants)
freebsd/freebsd 6.0_p5_release
freebsd/freebsd 7.0 (2 CPE variants)
freebsd/freebsd 7.0_beta4
freebsd/freebsd 7.0_releng
netbsd/netbsd 4.0
Published Mar 27, 2008
Tracked Since Feb 18, 2026