VulnerabilityModified
CVE-1999-1330
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
MEDIUM 4.6EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- debian/debian linux · redhat/linux
- Source
- cve@mitre.org
References
- http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html
- http://marc.info/?l=bugtraq&m=87602661419259&w=2
- http://www.iss.net/security_center/static/7244.php
- http://www.redhat.com/support/errata/rh42-errata-general.html#db
- http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html
- http://marc.info/?l=bugtraq&m=87602661419259&w=2
- http://www.iss.net/security_center/static/7244.php
- http://www.redhat.com/support/errata/rh42-errata-general.html#db
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.