CVE-2023-25139
CVSS V2 None
CVSS V3 None
Description
sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated string representation of a number, if the buffer is allocated the exact size required to represent that number as a string. For example, 1,234,567 (with padding to 13) overflows by two bytes.
Overview
- CVE ID
- CVE-2023-25139
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2023-02-03T06:15:09
- Last Modified Date
- 2023-03-02T16:15:14
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:gnu:glibc:2.37:*:*:*:*:*:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
http://www.openwall.com/lists/oss-security/2023/02/10/1 | |
https://security.netapp.com/advisory/ntap-20230302-0010/ | |
https://sourceware.org/bugzilla/show_bug.cgi?id=30068 | Exploit Issue Tracking Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-25139 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25139 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 07:08:44 | Added to TrackCVE | |||
2023-04-17 07:08:46 | Weakness Enumeration | new |