PT-2009-6716 · Wxwidgets+2 · Wxwidgets+2

Published

1970-01-01

·

Updated

2017-08-17

·

CVE-2009-2369

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wx2.6-doc versions prior to the fixed version wx2.4-i18n versions prior to the fixed version wxGTK versions prior to 2.8.10.1-r1 wx2.6-i18n versions prior to the fixed version libwxbase2.8-dbg versions prior to the fixed version wx2.4-examples versions prior to the fixed version libwxgtk2.8-0 versions prior to the fixed version libwxbase2.4-dbg versions prior to the fixed version wx2.6-headers versions prior to the fixed version libwxgtk2.6-dev versions prior to the fixed version wx2.8-doc versions prior to the fixed version wx2.4-headers versions prior to the fixed version wx2.4-doc versions prior to the fixed version wx2.6-examples versions prior to the fixed version libwxbase2.6-dev versions prior to the fixed version wx-common versions prior to the fixed version libwxbase2.8-0 versions prior to the fixed version libwxgtk2.8-dbg versions prior to the fixed version libwxbase2.4-1 versions prior to the fixed version libwxgtk2.6-0 versions prior to the fixed version libwxbase2.6-dbg versions prior to the fixed version libwxgtk2.8-dev versions prior to the fixed version libwxgtk2.6-dbg versions prior to the fixed version libwxgtk2.4-dbg versions prior to the fixed version libwxgtk2.4-dev versions prior to the fixed version libwxgtk2.4-1 versions prior to the fixed version wx2.8-examples versions prior to the fixed version libwxgtk2.4-1-contrib versions prior to the fixed version libwxbase2.8-dev versions prior to the fixed version libwxbase2.4-dev versions prior to the fixed version libwxbase2.6-0 versions prior to the fixed version wx2.8-i18n versions prior to the fixed version wx2.8-headers versions prior to the fixed version libwxgtk2.4-contrib-dev versions prior to the fixed version
Description The issue is related to multiple vulnerabilities in various wxWidgets packages in Debian GNU/Linux and Gentoo Linux. These vulnerabilities can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely. In the case of wxWidgets 2.8.10, an integer overflow in the wxImage::Create function allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03405
BDU:2015-03406
BDU:2015-03407
BDU:2015-03408
BDU:2015-03409
BDU:2015-03410
BDU:2015-03411
BDU:2015-03412
BDU:2015-03413
BDU:2015-03414
BDU:2015-03415
BDU:2015-03416
BDU:2015-03417
BDU:2015-03418
BDU:2015-03419
BDU:2015-03420
BDU:2015-03421
BDU:2015-03422
BDU:2015-03423
BDU:2015-03424
BDU:2015-03425
BDU:2015-03426
BDU:2015-03427
BDU:2015-03428
BDU:2015-03429
BDU:2015-03430
BDU:2015-03431
BDU:2015-03432
BDU:2015-03433
BDU:2015-03434
BDU:2015-03435
BDU:2015-03436
BDU:2015-03437
BDU:2015-09405
CVE-2009-2369
DSA-1890-1

Affected Products

Debian
Gentoo Linux
Wxwidgets