Lucene search

K
centosCentOS ProjectCESA-2009:1463
HistorySep 25, 2009 - 8:12 a.m.

newt security update

2009-09-2508:12:51
CentOS Project
lists.centos.org
46

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%

CentOS Errata and Security Advisory CESA-2009:1463

Newt is a programming library for color text mode, widget-based user
interfaces. Newt can be used to add stacked windows, entry widgets,
checkboxes, radio buttons, labels, plain text fields, scrollbars, and so
on, to text mode user interfaces.

A heap-based buffer overflow flaw was found in the way newt processes
content that is to be displayed in a text dialog box. A local attacker
could issue a specially-crafted text dialog box display request (direct or
via a custom application), leading to a denial of service (application
crash) or, potentially, arbitrary code execution with the privileges of the
user running the application using the newt library. (CVE-2009-2905)

Users of newt should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, all applications using the newt library must be restarted for the
update to take effect.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2009-October/078418.html
https://lists.centos.org/pipermail/centos-announce/2009-October/078419.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078333.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078334.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078335.html
https://lists.centos.org/pipermail/centos-announce/2009-September/078336.html

Affected packages:
newt
newt-debuginfo
newt-devel

Upstream details at:
https://access.redhat.com/errata/RHSA-2009:1463

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%