Integer Overflow Vulnerabilities in BSD libc Affecting Multiple Platforms and Vendors
CVE-2008-1391

Currently unrated

Key Information:

Vendor

FreeBSD

Vendor
CVE Published:
27 March 2008

What is CVE-2008-1391?

The libc implementation in various BSD operating systems, including NetBSD and FreeBSD, contains multiple integer overflow vulnerabilities. These flaws can be exploited by context-dependent attackers to execute arbitrary code. The vulnerabilities arise in the input handling of functions like strfmon and printf, where large integer values in format arguments can lead to unexpected behaviors, potentially allowing for code execution. Users of affected systems are recommended to apply patches or updates to mitigate the risks associated with these vulnerabilities.

References

EPSS Score

18% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.