CVE-2009-2416

EUVD-2009-2412
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxml
1.8.17
xmlsoftlibxml2
2.5.10
xmlsoftlibxml2
2.6.16
xmlsoftlibxml2
2.6.26
xmlsoftlibxml2
2.6.27
xmlsoftlibxml2
2.6.32
debiandebian_linux
4.0
redhatenterprise_linux
3.0
redhatenterprise_linux
4.0
redhatenterprise_linux
5.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
googlechrome
𝑥
< 2.0.172.43
applesafari
𝑥
< 4.0.4
appleiphone_os
2.0 ≤
𝑥
< 4.0
applemac_os_x
𝑥
< 10.4.11
applemac_os_x
10.5.0 ≤
𝑥
< 10.5.8
applemac_os_x
10.6.0 ≤
𝑥
< 10.6.2
applemac_os_x_server
𝑥
< 10.4.11
applemac_os_x_server
10.5.0 ≤
𝑥
< 10.5.8
applemac_os_x_server
10.6.0 ≤
𝑥
< 10.6.2
opensuseopensuse
10.3 ≤
𝑥
≤ 11.1
suselinux_enterprise
10.0
suselinux_enterprise
11.0
vmwarevcenter_server
4.0
vmwarevma
4.0
vmwareesx
3.0.3
vmwareesx
3.5
vmwareesx
4.0
vmwareesxi
3.5
vmwareesxi
4.0
sunopenoffice.org
2.0.0 ≤
𝑥
< 2.4.3
sunopenoffice.org
3.0.0 ≤
𝑥
< 3.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml
dapper
ignored
hardy
Fixed 1:1.8.17-14.1ubuntu0.1
released
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
libxml2
dapper
Fixed 2.6.24.dfsg-1ubuntu1.5
released
hardy
Fixed 2.6.31.dfsg-2ubuntu1.4
released
intrepid
Fixed 2.6.32.dfsg-4ubuntu1.2
released
jaunty
Fixed 2.6.32.dfsg-5ubuntu4.2
released
karmic
not-affected
lucid
not-affected
References