imPC@ndo IT

Tracker / CVE-2009-2416

CVE-2009-2416

Medium 6.5

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Affected products and versions

apple iphone_os · 2.0 → 4.0
apple mac_os_x · … → 10.4.11
apple mac_os_x · 10.5.0 → 10.5.8
apple mac_os_x · 10.6.0 → 10.6.2
apple mac_os_x_server · … → 10.4.11
apple mac_os_x_server · 10.5.0 → 10.5.8
apple mac_os_x_server · 10.6.0 → 10.6.2
apple safari · … → 4.0.4
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
google chrome · … → 2.0.172.43
opensuse opensuse · 10.3 → 11.1
redhat enterprise_linux
sun openoffice.org · 2.0.0 → 2.4.3
sun openoffice.org · 3.0.0 → 3.1.1
suse linux_enterprise
suse linux_enterprise_server
vmware esx
vmware esxi
vmware vcenter_server
vmware vma
xmlsoft libxml
xmlsoft libxml2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References