PT-2009-6724 · Red Hat+1 · Libnewt-Pic+6

Miroslav Lichvar

·

Published

1970-01-01

·

Updated

2024-08-09

·

CVE-2009-2905

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions newt versions 0.51.5 through 0.52.2 newt-devel versions 0.51.5 through 0.52.2 libnewt0 versions prior to 0.52.10-r1 libnewt-dev versions prior to 0.52.10-r1 libnewt-pic versions prior to 0.52.10-r1
Description The issue is related to a heap-based buffer overflow in the textbox.c file of the newt package, which can be exploited locally to cause a denial of service or possibly execute arbitrary code via a crafted text dialog box request. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a local attacker.
Recommendations For newt versions 0.51.5 through 0.52.2, update to version 0.52.10-r1 or later. For newt-devel versions 0.51.5 through 0.52.2, update to version 0.52.10-r1 or later. For libnewt0, libnewt-dev, and libnewt-pic versions prior to 0.52.10-r1, update to version 0.52.10-r1 or later. As a temporary workaround, consider restricting access to the vulnerable newt package until a patch is available.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10557
AZL-44280
BDU:2015-04092
BDU:2015-04093
BDU:2015-04094
BDU:2015-06840
BDU:2015-06841
BDU:2015-06842
BDU:2015-06843
BDU:2015-06844
BDU:2015-06845
BDU:2015-08535
BDU:2015-08536
BDU:2015-08537
BDU:2015-08538
BDU:2015-08539
BDU:2015-08540
BDU:2015-09407
CVE-2009-2905
DSA-1894-1
OPENSUSE-SU-2024:10010-1
RHSA-2009:1463
RHSA-2009_1463

Affected Products

Alt Linux
Red Hat
Libnewt-Dev
Libnewt-Pic
Libnewt0
Newt
Newt-Devel