CVE-2009-4880
Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.
- Gnu Glibc
- ≤ 2.10.1, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.1, 2.1.1, 2.1.1.6, 2.1.2, 2.1.3, 2.1.9, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.10, 2.4, 2.5, 2.5.1, 2.6, 2.6.1, 2.7, 2.8, 2.9, 2.10
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 11.2% (96th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2010-06-01
CVE-2009-4880 at NVD
1 known exploit for CVE-2009-4880
Proof-of-concept code and exploit modules indexed by Sploitus