Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-1391

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.201
EPSS Ranking 95.2%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2008-1391
  • Freebsd » Freebsd » Version: 6.0
    cpe:2.3:o:freebsd:freebsd:6.0
  • Freebsd » Freebsd » Version: 6.0_p5_release
    cpe:2.3:o:freebsd:freebsd:6.0_p5_release
  • Freebsd » Freebsd » Version: 7.0
    cpe:2.3:o:freebsd:freebsd:7.0
  • Freebsd » Freebsd » Version: 7.0_beta4
    cpe:2.3:o:freebsd:freebsd:7.0_beta4
  • Freebsd » Freebsd » Version: 7.0_releng
    cpe:2.3:o:freebsd:freebsd:7.0_releng
  • Netbsd » Netbsd » Version: 4.0
    cpe:2.3:o:netbsd:netbsd:4.0


Contact Us

Shodan ® - All rights reserved