CVE
- Id
- 31508
- CVE No.
- CVE-2008-1391
- Status
- Candidate
- Description
- Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
- Phase
- Assigned (20080318)
- Votes
- None (candidate not yet proposed)
- Comments