SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0689

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD…

MEDIUM 6.8EPSS 28.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 28.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
28.05% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
k-meleon project/k-meleon · mozilla/firefox · mozilla/seamonkey · freebsd/freebsd · netbsd/netbsd · openbsd/openbsd
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.