OpenBSD 4.6 / NetBSD 5.0.1 - 'printf(1)' Format String Parsing Denial of Service
Author: Maksymilian Arciemowicz
type: dos
platform: bsd
port:
date_added: 2009-10-30
date_updated: 2014-05-12
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/36884/info
OpenBSD and NetBSD are prone to a denial-of-service vulnerability because they fail to properly parse format strings to the 'printf(1)' function.
An attacker can exploit this issue to cause applications using the vulnerable call to crash with a segmentation fault, denying service to legitimate users.
The following are reported vulnerable:
OpenBSD 4.6
NetBSD 5.0.1
printf %*********s 666