Vulnerabilities > CVE-2009-4012 - Numeric Errors vulnerability in Linux.Thai Libthai

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
linux-thai
CWE-189
critical
nessus

Summary

Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to (1) thbrk/thbrk.c and (2) thwbrk/thwbrk.c. NOTE: some of these details are obtained from third party information.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1971.NASL
    descriptionTim Starling discovered that libthai, a set of Thai language support routines, is vulnerable of integer/heap overflow. This vulnerability could allow an attacker to run arbitrary code by sending a very long string.
    last seen2020-06-01
    modified2020-06-02
    plugin id44836
    published2010-02-24
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/44836
    titleDebian DSA-1971-1 : libthai - integer overflow
  • NASL familyMandriva Local Security Checks
    NASL idMANDRIVA_MDVSA-2010-010.NASL
    descriptionMultiple vulnerabilities has been found and corrected in libthai : Tim Starling discovered that libthai, a set of Thai language support routines, is vulnerable of integer/heap overflow. This vulnerability could allow an attacker to run arbitrary code by sending a very long string (CVE-2009-4012). Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id44042
    published2010-01-18
    reporterThis script is Copyright (C) 2010-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/44042
    titleMandriva Linux Security Advisory : libthai (MDVSA-2010:010)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-887-1.NASL
    descriptionTim Starling discovered that LibThai did not correctly handle long strings. A remote attacker could use specially-formed strings to execute arbitrary code with the user
    last seen2020-06-01
    modified2020-06-02
    plugin id44058
    published2010-01-19
    reporterUbuntu Security Notice (C) 2010-2019 Canonical, Inc. / NASL script (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/44058
    titleUbuntu 8.04 LTS / 8.10 / 9.04 / 9.10 : libthai vulnerability (USN-887-1)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_1_LIBTHAI-100115.NASL
    descriptionvery long strings could lead to a heap buffer overflow in libthai
    last seen2020-06-01
    modified2020-06-02
    plugin id44368
    published2010-02-02
    reporterThis script is Copyright (C) 2010-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/44368
    titleopenSUSE Security Update : libthai (libthai-1808)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_0_LIBTHAI-100115.NASL
    descriptionvery long strings could lead to a heap buffer overflow in libthai
    last seen2020-06-01
    modified2020-06-02
    plugin id44362
    published2010-02-02
    reporterThis script is Copyright (C) 2010-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/44362
    titleopenSUSE Security Update : libthai (libthai-1808)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_2_LIBTHAI-100115.NASL
    descriptionvery long strings could lead to a heap buffer overflow in libthai
    last seen2020-06-01
    modified2020-06-02
    plugin id44372
    published2010-02-02
    reporterThis script is Copyright (C) 2010-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/44372
    titleopenSUSE Security Update : libthai (libthai-1808)