Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
2009-08-11T18:30:00.983
2025-04-09T00:30:58.490
Deferred
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xmlsoft | libxml | 1.8.17 | Yes |
Application | xmlsoft | libxml2 | 2.5.10 | Yes |
Application | xmlsoft | libxml2 | 2.6.16 | Yes |
Application | xmlsoft | libxml2 | 2.6.26 | Yes |
Application | xmlsoft | libxml2 | 2.6.27 | Yes |
Application | xmlsoft | libxml2 | 2.6.32 | Yes |
Operating System | fedoraproject | fedora | 10 | Yes |
Operating System | fedoraproject | fedora | 11 | Yes |
Operating System | debian | debian_linux | 4.0 | Yes |
Operating System | redhat | enterprise_linux | 3.0 | Yes |
Operating System | redhat | enterprise_linux | 4.0 | Yes |
Operating System | redhat | enterprise_linux | 5.0 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | canonical | ubuntu_linux | 8.04 | Yes |
Operating System | canonical | ubuntu_linux | 8.10 | Yes |
Operating System | canonical | ubuntu_linux | 9.04 | Yes |
Application | chrome | < 2.0.172.43 | Yes | |
Application | apple | safari | < 4.0.4 | Yes |
Operating System | apple | iphone_os | < 4.0 | Yes |
Operating System | apple | mac_os_x | < 10.4.11 | Yes |
Operating System | apple | mac_os_x | < 10.5.8 | Yes |
Operating System | apple | mac_os_x | < 10.6.2 | Yes |
Operating System | apple | mac_os_x_server | < 10.4.11 | Yes |
Operating System | apple | mac_os_x_server | < 10.5.8 | Yes |
Operating System | apple | mac_os_x_server | < 10.6.2 | Yes |
Operating System | opensuse | opensuse | ≤ 11.1 | Yes |
Operating System | suse | linux_enterprise | 10.0 | Yes |
Operating System | suse | linux_enterprise | 11.0 | Yes |
Operating System | suse | linux_enterprise_server | 9 | Yes |
Application | vmware | vcenter_server | 4.0 | Yes |
Application | vmware | vma | 4.0 | Yes |
Operating System | vmware | esx | 3.0.3 | Yes |
Operating System | vmware | esx | 3.5 | Yes |
Operating System | vmware | esx | 4.0 | Yes |
Operating System | vmware | esxi | 3.5 | Yes |
Operating System | vmware | esxi | 4.0 | Yes |
Application | sun | openoffice.org | < 2.4.3 | Yes |
Application | sun | openoffice.org | < 3.1.1 | Yes |