CVE-2009-2416
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- xmlsoft/libxml · xmlsoft/libxml2 · fedoraproject/fedora · debian/debian linux · redhat/enterprise linux · canonical/ubuntu linux · google/chrome · apple/safari · apple/iphone os · apple/mac os x · apple/mac os x server · opensuse/opensuse · suse/linux enterprise · suse/linux enterprise server · vmware/vcenter server · vmware/vma · vmware/esx · vmware/esxi · sun/openoffice.org
- Source
- secalert@redhat.com
References
- http://googlechromereleases.blogspot.com/2009/08/stable-update-security-fixes.htmlRelease Notes
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlMailing List
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.htmlMailing List
- http://secunia.com/advisories/35036Broken Link
- http://secunia.com/advisories/36207Broken Link
- http://secunia.com/advisories/36338Broken Link
- http://secunia.com/advisories/36417Broken Link
- http://secunia.com/advisories/36631Broken Link
- http://secunia.com/advisories/37346Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://support.apple.com/kb/HT3937Third Party Advisory
- http://support.apple.com/kb/HT3949Third Party Advisory
- http://support.apple.com/kb/HT4225Third Party Advisory
- http://www.cert.fi/en/reports/2009/vulnerability2009085.htmlBroken Link
- http://www.codenomicon.com/labs/xml/Broken Link
- http://www.debian.org/security/2009/dsa-1859Mailing List, Patch
- http://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg678527.htmlPatch
- http://www.networkworld.com/columnists/2009/080509-xml-flaw.htmlBroken Link
- http://www.openoffice.org/security/cves/CVE-2009-2414-2416.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36010Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-815-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/2420Broken Link
- http://www.vupen.com/english/advisories/2009/3184Broken Link
- http://www.vupen.com/english/advisories/2009/3217Broken Link
- http://www.vupen.com/english/advisories/2009/3316Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=515205Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.