PT-2009-6677 · Debian+3 · Kdelibs-Dbg+9

Alin Rad Pop

·

Published

1970-01-01

·

Updated

2018-11-02

·

CVE-2009-0689

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kdelibs4-doc versions (affected versions not specified) kdelibs4c2a versions (affected versions not specified) kdelibs versions (affected versions not specified) kdelibs-dbg versions (affected versions not specified) kdelibs4-dev versions (affected versions not specified) kdelibs-data versions (affected versions not specified) libc versions (affected versions not specified) Mono versions prior to 4.2
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including kdelibs4-doc, kdelibs4c2a, kdelibs, kdelibs-dbg, kdelibs4-dev, and kdelibs-data. These vulnerabilities can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information. Additionally, there is an array index error in the dtoa implementation in libc, which can cause a denial of service and possibly execute arbitrary code via a large precision value in the format argument to a printf function. In Mono, the float-parsing code is derived from vulnerable code and concerns the 'freelist' array, which can lead to a crash and potentially induce arbitrary code execution.
Recommendations For kdelibs4-doc, consider disabling the package until a patch is available. For kdelibs4c2a, restrict access to the package to minimize the risk of exploitation. For kdelibs, avoid using the package in sensitive operations until the issue is resolved. For kdelibs-dbg, consider disabling the package until a patch is available. For kdelibs4-dev, restrict access to the package to minimize the risk of exploitation. For kdelibs-data, avoid using the package in sensitive operations until the issue is resolved. For libc, consider updating to a newer version that contains a fix for the array index error. For Mono, update to version 4.2 or later to resolve the float-parsing code issue. At the moment, there is no information about a newer version that contains a fix for the kdelibs4-doc, kdelibs4c2a, kdelibs, kdelibs-dbg, kdelibs4-dev, and kdelibs-data vulnerabilities.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02142
BDU:2015-02144
BDU:2015-02145
BDU:2015-02147
BDU:2015-02610
BDU:2015-02611
CVE-2009-0689
DLA-1564-1
DLA-376-1
DSA-1931-1
DSA-1998-1
MGASA-2016-0013
OPENSUSE-SU-2024:10394-1
RHSA-2009:1530
RHSA-2009:1531
RHSA-2009:1601
RHSA-2009_1530
RHSA-2009_1531
RHSA-2009_1601
RHSA-2010:0153
RHSA-2010:0154
RHSA-2010_0153
RHSA-2010_0154
RHSA-2014:0311
RHSA-2014:0312
RHSA-2014_0311
SUSE-SU-2013_1828-1
SUSE-SU-2016:0257-1
SUSE-SU-2016:2958-1
SUSE-SU-2016_0257-1
SUSE-SU-2016_2958-1

Affected Products

Mono
Red Hat
Suse
Kdelibs
Kdelibs-Data
Kdelibs-Dbg
Kdelibs4-Dev
Kdelibs4-Doc
Kdelibs4C2A
Libc