CVE-2009-0689
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 28.05% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- k-meleon project/k-meleon · mozilla/firefox · mozilla/seamonkey · freebsd/freebsd · netbsd/netbsd · openbsd/openbsd
- Source
- cret@cert.org
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.hPatch
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2014-0311.html
- http://rhn.redhat.com/errata/RHSA-2014-0312.html
- http://secunia.com/advisories/37431Vendor Advisory
- http://secunia.com/advisories/37682Vendor Advisory
- http://secunia.com/advisories/37683Vendor Advisory
- http://secunia.com/advisories/38066Vendor Advisory
- http://secunia.com/advisories/38977Vendor Advisory
- http://secunia.com/advisories/39001Vendor Advisory
- http://secunia.com/secunia_research/2009-35/Vendor Advisory
- http://securityreason.com/achievement_securityalert/63Exploit
- http://securityreason.com/achievement_securityalert/69
- http://securityreason.com/achievement_securityalert/71
- http://securityreason.com/achievement_securityalert/72
- http://securityreason.com/achievement_securityalert/73
- http://securityreason.com/achievement_securityalert/75
- http://securityreason.com/achievement_securityalert/76
- http://securityreason.com/achievement_securityalert/77
- http://securityreason.com/achievement_securityalert/78
- http://securityreason.com/achievement_securityalert/81
- http://securitytracker.com/id?1022478Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1
- http://support.apple.com/kb/HT4077
- http://support.apple.com/kb/HT4225
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:294
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:330
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.