CVE-2009-0689
Last modified
CVE-2009-0689 is a vulnerability of currently unknown severity. Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.. EPSS estimates a 28.17% chance of exploitation in the next 30 days.
Description
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| K-Meleon Project | K-Meleon | 1.5.3 |
| Mozilla | Firefox | 3.0.1 |
| Mozilla | Firefox | 3.0.2 |
| Mozilla | Firefox | 3.0.3 |
| Mozilla | Firefox | 3.0.4 |
| Mozilla | Firefox | 3.0.5 |
| Mozilla | Firefox | 3.0.6 |
| Mozilla | Firefox | 3.0.7 |
| Mozilla | Firefox | 3.0.8 |
| Mozilla | Firefox | 3.0.9 |
| Mozilla | Firefox | 3.0.10 |
| Mozilla | Firefox | 3.0.11 |
| Mozilla | Firefox | 3.0.12 |
| Mozilla | Firefox | 3.0.13 |
| Mozilla | Firefox | 3.0.14 |
| Mozilla | Firefox | 3.5 |
| Mozilla | Firefox | 3.5.1 |
| Mozilla | Firefox | 3.5.2 |
| Mozilla | Firefox | 3.5.3 |
| Mozilla | Seamonkey | 1.1.8 |
| Freebsd | Freebsd | 6.4 |
| Freebsd | Freebsd | 7.2 |
| Netbsd | Netbsd | 5.0 |
| Openbsd | Openbsd | 4.5 |
References
- http://secunia.com/advisories/37431Vendor Advisory
- http://secunia.com/advisories/37682Vendor Advisory
- http://secunia.com/advisories/37683Vendor Advisory
- http://secunia.com/advisories/38066Vendor Advisory
- http://secunia.com/advisories/38977Vendor Advisory
- http://secunia.com/advisories/39001Vendor Advisory
- http://secunia.com/secunia_research/2009-35/Vendor Advisory
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.cPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35510Exploit, Patch
- http://www.vupen.com/english/advisories/2009/3297Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3299Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3334Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0094Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0648Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0650Vendor Advisory
- http://secunia.com/advisories/37431Vendor Advisory
- http://secunia.com/advisories/37682Vendor Advisory
- http://secunia.com/advisories/37683Vendor Advisory
- http://secunia.com/advisories/38066Vendor Advisory
- http://secunia.com/advisories/38977Vendor Advisory
- http://secunia.com/advisories/39001Vendor Advisory
- http://secunia.com/secunia_research/2009-35/Vendor Advisory
- http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.cPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35510Exploit, Patch
- http://www.vupen.com/english/advisories/2009/3297Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3299Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3334Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0094Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0648Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0650Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0689?
How severe is CVE-2009-0689?
How do I fix CVE-2009-0689?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0680cgi-bin/welcome/VPN_only in the web interface in Netgear SSL…
- CVE-2009-0681PGP Desktop before 9.10 allows local users to (1) cause a de…
- CVE-2009-0682vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys …
- CVE-2009-0686The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0…
- CVE-2009-0687The pf_test_rule function in OpenBSD Packet Filter (PF), as …
- CVE-2009-0688Multiple buffer overflows in the CMU Cyrus SASL library befo…
- CVE-2009-0690The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 …
- CVE-2009-0691The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 …
- CVE-2009-0692Stack-based buffer overflow in the script_write_params metho…
- CVE-2009-0693Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x…
- CVE-2009-0695hagent.exe in Wyse Device Manager (WDM) 4.7.x does not requi…
- CVE-2009-0696The dns_db_findrdataset function in db.c in named in ISC BIN…
Are you affected by CVE-2009-0689?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
