FEDORA-2012-11927Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085190.html CVE-2012-3480
GNU glibc - Multiple Local Stack Buffer Overflow Vulnerabilities
Record summary
CVE-2012-3480 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU glibc - Multiple Local Stack Buffer Overflow VulnerabilitiesExploitDB exploitby Joseph S. MyerNot analyzed1 file
References
Showing 12 of 2384710vdb entry
http://osvdb.org/84710 RHSA-2012:1207Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-1207.html RHSA-2012:1208Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-1208.html RHSA-2012:1262Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-1262.html RHSA-2012:1325Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-1325.html 50201Third-party advisory
http://secunia.com/advisories/50201 50422Third-party advisory
http://secunia.com/advisories/50422 sourceware.org
http://sourceware.org/bugzilla/show_bug.cgi?id=14459 [libc-alpha] 20120812 Fix strtod integer/buffer overflow (bug 14459)mailing list
http://sourceware.org/ml/libc-alpha/2012-08/msg00202.html [oss-security] 20120813 CVE Request -- glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routinesmailing list
http://www.openwall.com/lists/oss-security/2012/08/13/4 [oss-security] 20120813 Re: CVE Request -- glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routinesmailing list
http://www.openwall.com/lists/oss-security/2012/08/13/6