Sploitus

CVE-2008-1391

2 known exploits for CVE-2008-1391

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

Freebsd
= 6.0, 6.0_p5_release, 7.0, 7.0_beta4, 7.0_releng
Netbsd
= 4.0
CVSS 2.0
7.5 HIGH
EPSS
18.8% (97th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2008-03-27
CVE-2008-1391 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2008-1391

Proof-of-concept code and exploit modules indexed by Sploitus