CVE-2009-0689
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
Published:Jul 1, 2009
Last Modified:Apr 23, 2026
EPS:Jul 1, 2009
EPSS Score:0.4176
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Freebsd
Product
Freebsd
Freebsd
Freebsd
Vendor
K-meleon Project
Product
K-meleon
K-meleon Project
K-meleon
Vendor
Mozilla
Product
Firefox
Mozilla
Firefox
Vendor
Mozilla
Product
Seamonkey
Mozilla
Seamonkey
Vendor
Netbsd
Product
Netbsd
Netbsd
Netbsd
Vendor
Openbsd
Product
Openbsd
Openbsd
Openbsd
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Redhat
Product
Rhel Mission Critical
Redhat
Rhel Mission Critical
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
