CVE-2009-2416

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
xmlsoftlibxml
1.8.17
xmlsoftlibxml2
2.5.10
xmlsoftlibxml2
2.6.16
xmlsoftlibxml2
2.6.26
xmlsoftlibxml2
2.6.27
xmlsoftlibxml2
2.6.32
debiandebian_linux
4.0
redhatenterprise_linux
3.0
redhatenterprise_linux
4.0
redhatenterprise_linux
5.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
8.04
canonicalubuntu_linux
8.10
canonicalubuntu_linux
9.04
googlechrome
𝑥
< 2.0.172.43
applesafari
𝑥
< 4.0.4
appleiphone_os
2.0 ≤
𝑥
< 4.0
applemac_os_x
𝑥
< 10.4.11
applemac_os_x
10.5.0 ≤
𝑥
< 10.5.8
applemac_os_x
10.6.0 ≤
𝑥
< 10.6.2
applemac_os_x_server
𝑥
< 10.4.11
applemac_os_x_server
10.5.0 ≤
𝑥
< 10.5.8
applemac_os_x_server
10.6.0 ≤
𝑥
< 10.6.2
opensuseopensuse
10.3 ≤
𝑥
≤ 11.1
suselinux_enterprise
10.0
suselinux_enterprise
11.0
vmwarevcenter_server
4.0
vmwarevma
4.0
vmwareesx
3.0.3
vmwareesx
3.5
vmwareesx
4.0
vmwareesxi
3.5
vmwareesxi
4.0
sunopenoffice.org
2.0.0 ≤
𝑥
< 2.4.3
sunopenoffice.org
3.0.0 ≤
𝑥
< 3.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
Fixed 1:1.8.17-14.1ubuntu0.1
released
dapper
ignored
libxml2
lucid
not-affected
karmic
not-affected
jaunty
Fixed 2.6.32.dfsg-5ubuntu4.2
released
intrepid
Fixed 2.6.32.dfsg-4ubuntu1.2
released
hardy
Fixed 2.6.31.dfsg-2ubuntu1.4
released
dapper
Fixed 2.6.24.dfsg-1ubuntu1.5
released
References