CVE Database
/

CVE-2009-0689

Back to search

CVE-2009-0689

Published: Jul 1, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

VendorProductVersions

n/a

n/a

affected
n/a

References

20090625 Multiple Vendors libc/gdtoa printf(3) Array Overrun
third-party-advisory
x_refsource_SREASONRES
RHSA-2010:0153
vendor-advisory
x_refsource_REDHAT
MDVSA-2009:330
vendor-advisory
x_refsource_MANDRIVA
39001
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2009:018
vendor-advisory
x_refsource_SUSE
ADV-2010-0094
vdb-entry
x_refsource_VUPEN
ADV-2010-0648
vdb-entry
x_refsource_VUPEN
ADV-2010-0650
vdb-entry
x_refsource_VUPEN
272909
vendor-advisory
x_refsource_SUNALERT
ADV-2009-3299
vdb-entry
x_refsource_VUPEN
RHSA-2009:1601
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2010-03-29-1
vendor-advisory
x_refsource_APPLE
SUSE-SR:2010:013
vendor-advisory
x_refsource_SUSE
RHSA-2014:0312
vendor-advisory
x_refsource_REDHAT
37683
third-party-advisory
x_refsource_SECUNIA
38977
third-party-advisory
x_refsource_SECUNIA
RHSA-2010:0154
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:6528
vdb-entry
signature
x_refsource_OVAL
37682
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9541
vdb-entry
signature
x_refsource_OVAL
38066
third-party-advisory
x_refsource_SECUNIA
USN-915-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0311
vendor-advisory
x_refsource_REDHAT
ADV-2009-3297
vdb-entry
x_refsource_VUPEN
37431
third-party-advisory
x_refsource_SECUNIA
20100108 MacOS X 10.5/10.6 libc/strtod(3) buffer overflow
third-party-advisory
x_refsource_SREASONRES
1022478
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2010-06-21-1
vendor-advisory
x_refsource_APPLE
ADV-2009-3334
vdb-entry
x_refsource_VUPEN
20091211 Sunbird 0.9 Array Overrun (code execution)
third-party-advisory
x_refsource_SREASONRES
MDVSA-2009:294
vendor-advisory
x_refsource_MANDRIVA
35510
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now