Submitted by MarcDeslauriers on Thu, 2009-09-24 13:41
Referenced CVEs:
CVE-2009-2905
Description:
===========================================================
Ubuntu Security Notice USN-837-1 September 24, 2009
newt vulnerability
CVE-2009-2905
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libnewt0.51 0.51.6-31ubuntu1.1
Ubuntu 8.04 LTS:
libnewt0.52 0.52.2-11.2ubuntu1.1
Ubuntu 8.10:
libnewt0.52 0.52.2-11.3ubuntu1.1
Ubuntu 9.04:
libnewt0.52 0.52.2-11.3ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Miroslav Lichvar discovered that Newt incorrectly handled rendering in a
text box. An attacker could exploit this and cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program.


