MPFR 'strtofr.c' Buffer Overflow Vulnerability
BID:71542
CVE-2014-9474 |Info
MPFR 'strtofr.c' Buffer Overflow Vulnerability
| Bugtraq ID: | 71542 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-9474 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2014 12:00AM |
| Updated: | Feb 02 2016 08:09PM |
| Credit: | Vincent Lefevre |
| Vulnerable: |
MPFR MPFR 3.1.2 MPFR MPFR 2.4.1 MPFR MPFR 2.4 MPFR MPFR 2.1 MPFR MPFR 3.1.2-p10 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 GMP GMP 5.1.3 Gentoo Linux |
| Not Vulnerable: |
MPFR MPFR 3.1.2-p11 |
Discussion
MPFR 'strtofr.c' Buffer Overflow Vulnerability
MPFR is prone to a buffer overflow vulnerability because it fails to adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the affected function. Failed exploit attempts will likely crash the application.
MPFR is prone to a buffer overflow vulnerability because it fails to adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the affected function. Failed exploit attempts will likely crash the application.
Solution / Fix
MPFR 'strtofr.c' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64mpfr-devel-3.1.0-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64mpfr-static-devel-3.1.0-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64mpfr4-3.1.0-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
MPFR 'strtofr.c' Buffer Overflow Vulnerability
References:
References:
- Bug 1171701 - mpfr: buffer overflow in mpfr_strtof (Red Hat Bugzilla)
- CVE request: mpfr: buffer overflow in mpfr_strtofr (Vasyl Kaigorodov)
- Debian Bug report logs - #772008 libmpfr4: buffer overflow in mpfr_strtofr (Vincent Lefevre)
- MPFR Homepage (MPFR)