PT-2009-1015 · Xml+2 · Libxml2+2
Iankko
+1
·
Published
2009-08-10
·
Updated
2023-02-13
·
CVE-2009-2414
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libxml2 versions 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32
libxml version 1.8.17
libxml2 versions prior to 2.7.3
Description
The issue is related to a stack consumption vulnerability in libxml2, allowing context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD. This is related to a function recursion. The vulnerability can be exploited remotely, leading to a disruption of protected information.
Recommendations
For libxml2 versions 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, update to version 2.7.3 or later.
For libxml version 1.8.17, update to a version later than 1.8.17.
For libxml2 versions prior to 2.7.3, update to version 2.7.3 or later.
As a temporary workaround, consider restricting the use of the
libxml2 library until a patch is available.Exploit
Fix
DoS
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Libxml
Libxml2