ID:11452 - Exploit for Input validation error in Glibc - CVE-2009-4880

 
Main Vulnerability Database Exploits ID:11452 - Exploit for Input validation error in Glibc - CVE-2009-4880

ID:11452 - Exploit for Input validation error in Glibc - CVE-2009-4880

Published: June 3, 2025


Vulnerability identifier: #VU110125
Vulnerability risk: Medium
CVE-ID: CVE-2009-4880
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Glibc

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.


Remediation

Install update from vendor's website.