Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1391
Description:Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context- dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
Test IDs: 1.3.6.1.4.1.25623.1.0.67525  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1391
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html
BugTraq ID: 28479
http://www.securityfocus.com/bid/28479
Bugtraq: 20080327 [securityreason] *BSD libc (strfmon) Multiple vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/490158/100/0/threaded
Cert/CC Advisory: TA08-350A
http://www.us-cert.gov/cas/techalerts/TA08-350A.html
Debian Security Information: DSA-2058 (Google Search)
http://www.debian.org/security/2010/dsa-2058
http://www.securitytracker.com/id?1019722
http://secunia.com/advisories/29574
http://secunia.com/advisories/33179
http://securityreason.com/securityalert/3770
http://securityreason.com/achievement_securityalert/53
SuSE Security Announcement: SUSE-SA:2010:052 (Google Search)
https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html
http://www.vupen.com/english/advisories/2008/3444
XForce ISS Database: bsd-strfmon-overflow(41504)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41504




© 1998-2025 E-Soft Inc. All rights reserved.