Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
2009-08-11T18:30:00.937
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | xmlsoft | libxml | 1.8.17 | Yes |
| Application | xmlsoft | libxml2 | 2.5.10 | Yes |
| Application | xmlsoft | libxml2 | 2.6.16 | Yes |
| Application | xmlsoft | libxml2 | 2.6.26 | Yes |
| Application | xmlsoft | libxml2 | 2.6.27 | Yes |
| Application | xmlsoft | libxml2 | 2.6.32 | Yes |