OpenBSD 4.6 / NetBSD 5.0.1 - 'printf(1)' Format String Parsing Denial of Service

EDB-ID:

33318

CVE:

N/A




Platform:

BSD

Date:

2009-10-30


source: https://www.securityfocus.com/bid/36884/info

OpenBSD and NetBSD are prone to a denial-of-service vulnerability because they fail to properly parse format strings to the 'printf(1)' function.

An attacker can exploit this issue to cause applications using the vulnerable call to crash with a segmentation fault, denying service to legitimate users.

The following are reported vulnerable:

OpenBSD 4.6
NetBSD 5.0.1

printf %*********s 666