PT-2009-1015 · Xml+2 · Libxml2+2

Iankko

+1

·

Published

2009-08-10

·

Updated

2023-02-13

·

CVE-2009-2414

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32 libxml version 1.8.17 libxml2 versions prior to 2.7.3
Description The issue is related to a stack consumption vulnerability in libxml2, allowing context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD. This is related to a function recursion. The vulnerability can be exploited remotely, leading to a disruption of protected information.
Recommendations For libxml2 versions 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, update to version 2.7.3 or later. For libxml version 1.8.17, update to a version later than 1.8.17. For libxml2 versions prior to 2.7.3, update to version 2.7.3 or later. As a temporary workaround, consider restricting the use of the libxml2 library until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2015-02612
BDU:2015-02613
BDU:2015-09406
CVE-2009-2414
DSA-1859-1
DSA-1861-1
RHSA-2009:1206
RHSA-2009_1206

Affected Products

Red Hat
Libxml
Libxml2