CVE-2009-2905
Summary
| CVE | CVE-2009-2905 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-29 19:30:00 UTC |
| Updated | 2017-09-19 01:29:00 UTC |
| Description | Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fedorahosted | Newt | 0.51.5 | All | All | All |
| Application | Fedorahosted | Newt | 0.51.6 | All | All | All |
| Application | Fedorahosted | Newt | 0.52.2 | All | All | All |
| Application | Fedorahosted | Newt | 0.51.5 | All | All | All |
| Application | Fedorahosted | Newt | 0.51.6 | All | All | All |
| Application | Fedorahosted | Newt | 0.52.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| VMware ESX Server 4 update for newt, nfs-utils, and glib2 - Advisories - Community | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| USN-837-1: Newt vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Avaya Products Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| VMware vMA Update for Multiple Packages - Advisories - Community | SECUNIA | secunia.com | |
| 523955 – (CVE-2009-2905) CVE-2009-2905 newt: heap-overflow in textbox when text reflowing | CONFIRM | bugzilla.redhat.com | |
| access.redhat.com | REDHAT | rhn.redhat.com | |
| Newt Text Box Content Processing Remote Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| [Security-announce] VMSA-2010-0004 ESX Service Console and vMA third party updates | MLIST | lists.vmware.com | |
| 404 Not Found | CONFIRM | security.debian.org | Patch |
| Debian -- Security Information -- DSA-1894-1 newt | DEBIAN | www.debian.org | Patch |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | CONFIRM | kb.juniper.net | |
| ASA-2009-476 (RHSA-2009-1463) | CONFIRM | support.avaya.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.