Description
The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe.
Affected products
- Avaya / libsafe1.3.4 – 1.3.4
- Avaya / libsafe1.3.8 – 1.3.8
- Avaya / libsafe2.0.2 – 2.0.2
- Avaya / libsafe2.0.5 – 2.0.5
- Avaya / libsafe2.0.9 – 2.0.9
- Avaya / libsafe2.0.10 – 2.0.10
- Avaya / libsafe2.0.11 – 2.0.11