Buffer Length Calculation Issue in GNU C Library Affects Glibc
CVE-2012-3404
Currently unrated
Key Information:
- Vendor
Canonical
- Vendor
- CVE Published:
- 10 February 2014
What is CVE-2012-3404?
A vulnerability exists in the GNU C Library that improperly calculates buffer lengths in the vfprintf function, which may permit context-dependent attackers to bypass FORTIFY_SOURCE protections. This flaw opens the door to denial of service attacks, manifested as stack corruption and application crashes when format strings utilize positional parameters and multiple format specifiers. Comprehensive remediation is crucial to mitigate potential exploitation.