Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2414


Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.


Published

2009-08-11T18:30:00.937

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xmlsoft libxml 1.8.17 Yes
Application xmlsoft libxml2 2.5.10 Yes
Application xmlsoft libxml2 2.6.16 Yes
Application xmlsoft libxml2 2.6.26 Yes
Application xmlsoft libxml2 2.6.27 Yes
Application xmlsoft libxml2 2.6.32 Yes

References