Summary
The remote host is missing an update to newt
announced via advisory USN-837-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
libnewt0.51 0.51.6-31ubuntu1.1
Ubuntu 8.04 LTS:
libnewt0.52 0.52.2-11.2ubuntu1.1
Ubuntu 8.10:
libnewt0.52 0.52.2-11.3ubuntu1.1
Ubuntu 9.04:
libnewt0.52 0.52.2-11.3ubuntu3.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-837-1
Insight
Miroslav Lichvar discovered that Newt incorrectly handled rendering in a text box. An attacker could exploit this and cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program.
Severity
Classification
-
CVE CVE-2009-2905 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities