The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe.
| Software | From | Fixed in |
|---|---|---|
| avaya / libsafe | 2.0.5 | 2.0.5.x |
| avaya / libsafe | 2.0.9 | 2.0.9.x |
| avaya / libsafe | 2.0.2 | 2.0.2.x |
| avaya / libsafe | 1.3.4 | 1.3.4.x |
| avaya / libsafe | 2.0.11 | 2.0.11.x |
| avaya / libsafe | 2.0.10 | 2.0.10.x |
| avaya / libsafe | 1.3.8 | 1.3.8.x |