Sploitus

CVE-2009-4880

1 known exploit for CVE-2009-4880

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.

Affected products
Glibc, Libc6
Gnu Glibc
≤ 2.10.1, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.1, 2.1.1, 2.1.1.6, 2.1.2, 2.1.3, 2.1.9, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.10, 2.4, 2.5, 2.5.1, 2.6, 2.6.1, 2.7, 2.8, 2.9, 2.10
CVSS 2.0
5.0 MEDIUM
EPSS
11.2% (96th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2010-06-01
CVE-2009-4880 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2009-4880

Proof-of-concept code and exploit modules indexed by Sploitus