CVE-2009-0689

EUVD-2009-0689
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
k-meleon_projectk-meleon
1.5.3
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.0.12
mozillafirefox
3.0.13
mozillafirefox
3.0.14
mozillafirefox
3.5
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
mozillaseamonkey
1.1.8
freebsdfreebsd
6.4
freebsdfreebsd
6.4:release
freebsdfreebsd
6.4:release_p2
freebsdfreebsd
6.4:release_p3
freebsdfreebsd
6.4:release_p4
freebsdfreebsd
6.4:release_p5
freebsdfreebsd
6.4:stable
freebsdfreebsd
7.2
freebsdfreebsd
7.2:pre-release
freebsdfreebsd
7.2:stable
netbsdnetbsd
5.0
openbsdopenbsd
4.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mono
bookworm
6.8.0.105+dfsg-3.3
fixed
bullseye
6.8.0.105+dfsg-3.3~deb11u1
fixed
lenny
no-dsa
sid
6.12.0.199+dfsg-2
fixed
trixie
6.12.0.199+dfsg-2
fixed
wheezy
no-dsa
nspr
bookworm
2:4.35-1
fixed
bullseye
2:4.29-1
fixed
lenny
no-dsa
sid
2:4.35-1.1
fixed
trixie
2:4.35-1.1
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kde4libs
dapper
dne
hardy
ignored
intrepid
Fixed 4:4.1.4-0ubuntu1~intrepid1.5
released
jaunty
Fixed 4:4.2.2-0ubuntu5.4
released
karmic
Fixed 4:4.3.2-0ubuntu7.2
released
lucid
Fixed 4:3.5.10.dfsg.1-2.1ubuntu4
released
kdelibs
dapper
ignored
hardy
Fixed 4:3.5.10-0ubuntu1~hardy1.5
released
intrepid
Fixed 4:3.5.10-0ubuntu6.4
released
jaunty
Fixed 4:3.5.10.dfsg.1-1ubuntu8.4
released
karmic
Fixed 4:3.5.10.dfsg.1-2ubuntu7.2
released
lucid
Fixed 4:3.5.10.dfsg.1-2.1ubuntu4
released
thunderbird
dapper
dne
hardy
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.10.1
released
lucid
not-affected
References