Description
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
References (36)
Core 36
Core References
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-815-1
Mailing List vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00537.html
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36631
Broken Link vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9262
Broken Link x_refsource_misc
http://www.networkworld.com/columnists/2009/080509-xml-flaw.html
Issue Tracking, Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=515205
Third Party Advisory x_refsource_confirm
http://www.openoffice.org/security/cves/CVE-2009-2414-2416.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html
Broken Link vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3217
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37471
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT4225
Broken Link vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2420
Mailing List vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00642.html
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36417
Broken Link x_refsource_misc
http://www.cert.fi/en/reports/2009/vulnerability2009085.html
Broken Link x_refsource_misc
http://www.codenomicon.com/labs/xml/
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3949
Patch mailing-list
x_refsource_mlist
http://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg678527.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36010
Release Notes x_refsource_confirm
http://googlechromereleases.blogspot.com/2009/08/stable-update-security-fixes.html
Broken Link, Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507985/100/0/threaded
Patch x_refsource_confirm
https://git.gnome.org/browse/libxml2/commit/?id=489f9671e71cc44a97b23111b3126ac8a1e21a59
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35036
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36338
Mailing List vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00547.html
Broken Link vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7783
Broken Link vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3184
Mailing List, Patch vendor-advisory
x_refsource_debian
http://www.debian.org/security/2009/dsa-1859
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37346
Broken Link vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3316
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3937
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36207
Scores
CVSS v3
6.5
EPSS
0.0050
EPSS Percentile
66.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (33)
apple/iphone_os
2.0 - 4.0
apple/mac_os_x
< 10.4.11
apple/mac_os_x_server
< 10.4.11
apple/safari
< 4.0.4
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
8.10
canonical/ubuntu_linux
9.04
debian/debian_linux
4.0
fedoraproject/fedora
10
... and 23 more
Published
Aug 11, 2009
Tracked Since
Feb 18, 2026