CVE-2009-2905: Buffer Overflow
Published Sep 17, 2009
·Updated
Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.
Affected Software
3 affected components
fedorahosted Newt=0.51.6
fedorahosted Newt=0.52.2
fedorahosted Newt=0.51.5
Remediation
Patch Available
Event History
Sep 17, 2009
Data Sourced
11:48 AM
DescriptionSeverityAffected Software
Sep 29, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2905?
CVE-2009-2905 has a high severity rating due to potential for denial of service or arbitrary code execution.
2
How do I fix CVE-2009-2905?
To fix CVE-2009-2905, upgrade to a version of newt that is not affected, such as 0.52.3 or later.
3
What are the affected versions of newt for CVE-2009-2905?
The affected versions of newt for CVE-2009-2905 are 0.51.5, 0.51.6, and 0.52.2.
4
Is CVE-2009-2905 a remote or local vulnerability?
CVE-2009-2905 is a local vulnerability, meaning it can only be exploited by local users.
5
What type of vulnerability is CVE-2009-2905?
CVE-2009-2905 is classified as a heap-based buffer overflow vulnerability.