CVE Database
/

CVE-2012-3406

Back to search

CVE-2012-3406

Published: Feb 10, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2012:1200
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1097
vendor-advisory
x_refsource_REDHAT
GLSA-201503-04
vendor-advisory
x_refsource_GENTOO
RHSA-2012:1098
vendor-advisory
x_refsource_REDHAT
USN-1589-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2012:1185
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now