CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
10.1%
CentOS Errata and Security Advisory CESA-2009:1463
Newt is a programming library for color text mode, widget-based user
interfaces. Newt can be used to add stacked windows, entry widgets,
checkboxes, radio buttons, labels, plain text fields, scrollbars, and so
on, to text mode user interfaces.
A heap-based buffer overflow flaw was found in the way newt processes
content that is to be displayed in a text dialog box. A local attacker
could issue a specially-crafted text dialog box display request (direct or
via a custom application), leading to a denial of service (application
crash) or, potentially, arbitrary code execution with the privileges of the
user running the application using the newt library. (CVE-2009-2905)
Users of newt should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, all applications using the newt library must be restarted for the
update to take effect.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2009-October/078418.html
https://lists.centos.org/pipermail/centos-announce/2009-October/078419.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078333.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078334.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078335.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078336.html
Affected packages:
newt
newt-debuginfo
newt-devel
Upstream details at:
https://access.redhat.com/errata/RHSA-2009:1463
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 3 | i386 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.i386.rpm |
CentOS | 3 | i386 | newt-devel | < 0.51.5-2.el3 | newt-devel-0.51.5-2.el3.i386.rpm |
CentOS | 3 | i386 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.i386.rpm |
CentOS | 3 | i386 | newt-devel | < 0.51.5-2.el3 | newt-devel-0.51.5-2.el3.i386.rpm |
CentOS | 3 | i386 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.i386.rpm |
CentOS | 3 | x86_64 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.x86_64.rpm |
CentOS | 3 | x86_64 | newt-devel | < 0.51.5-2.el3 | newt-devel-0.51.5-2.el3.x86_64.rpm |
CentOS | 3 | i386 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.i386.rpm |
CentOS | 3 | x86_64 | newt | < 0.51.5-2.el3 | newt-0.51.5-2.el3.x86_64.rpm |
CentOS | 3 | x86_64 | newt-devel | < 0.51.5-2.el3 | newt-devel-0.51.5-2.el3.x86_64.rpm |