Oval Definition:oval:com.redhat.rhsa:def:20091463
Revision Date:2009-09-24Version:642
Title:RHSA-2009:1463: newt security update (Moderate)
Description:Newt is a programming library for color text mode, widget-based user interfaces. Newt can be used to add stacked windows, entry widgets, checkboxes, radio buttons, labels, plain text fields, scrollbars, and so on, to text mode user interfaces.

  • A heap-based buffer overflow flaw was found in the way newt processes content that is to be displayed in a text dialog box. A local attacker could issue a specially-crafted text dialog box display request (direct or via a custom application), leading to a denial of service (application crash) or, potentially, arbitrary code execution with the privileges of the user running the application using the newt library. (CVE-2009-2905)

    Users of newt should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, all applications using the newt library must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2905
    RHSA-2009:1463
    RHSA-2009:1463-01
    RHSA-2009:1463-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • newt-devel is earlier than 0:0.51.5-2.el3
  • AND newt-devel is signed with Red Hat master key
  • newt is earlier than 0:0.51.5-2.el3
  • AND newt is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • newt-devel is earlier than 0:0.51.6-10.el4_8.1
  • AND newt-devel is signed with Red Hat master key
  • newt is earlier than 0:0.51.6-10.el4_8.1
  • AND newt is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • newt-devel is earlier than 0:0.52.2-12.el5_4.1
  • AND newt-devel is signed with Red Hat redhatrelease key
  • newt is earlier than 0:0.52.2-12.el5_4.1
  • AND newt is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • newt is earlier than 0:0.51.6-10.el4_8.1
  • AND newt is signed with Red Hat redhatrelease2 key
  • newt-devel is earlier than 0:0.51.6-10.el4_8.1
  • AND newt-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • newt is earlier than 0:0.52.2-12.el5_4.1
  • AND newt is signed with Red Hat redhatrelease2 key
  • newt-devel is earlier than 0:0.52.2-12.el5_4.1
  • AND newt-devel is signed with Red Hat redhatrelease2 key
  • BACK