libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe.
| Software | From | Fixed in |
|---|---|---|
| avaya / libsafe | 2.0.5 | 2.0.5.x |
| avaya / libsafe | 2.0.9 | 2.0.9.x |
| avaya / libsafe | 2.0.2 | 2.0.2.x |
| avaya / libsafe | 1.3.4 | 1.3.4.x |
| avaya / libsafe | 2.0.11 | 2.0.11.x |
| avaya / libsafe | 2.0.10 | 2.0.10.x |
| avaya / libsafe | 1.3.8 | 1.3.8.x |