Tracker / CVE-2009-2416
CVE-2009-2416
Medium 6.5
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Affected products and versions
| apple | iphone_os · 2.0 → 4.0 |
|---|---|
| apple | mac_os_x · … → 10.4.11 |
| apple | mac_os_x · 10.5.0 → 10.5.8 |
| apple | mac_os_x · 10.6.0 → 10.6.2 |
| apple | mac_os_x_server · … → 10.4.11 |
| apple | mac_os_x_server · 10.5.0 → 10.5.8 |
| apple | mac_os_x_server · 10.6.0 → 10.6.2 |
| apple | safari · … → 4.0.4 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| fedoraproject | fedora |
| chrome · … → 2.0.172.43 | |
| opensuse | opensuse · 10.3 → 11.1 |
| redhat | enterprise_linux |
| sun | openoffice.org · 2.0.0 → 2.4.3 |
| sun | openoffice.org · 3.0.0 → 3.1.1 |
| suse | linux_enterprise |
| suse | linux_enterprise_server |
| vmware | esx |
| vmware | esxi |
| vmware | vcenter_server |
| vmware | vma |
| xmlsoft | libxml |
| xmlsoft | libxml2 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.