Tracker / CVE-2009-2416
CVE-2009-2416
Media 6.5
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Prodotti e versioni affette
| apple | iphone_os · 2.0 → 4.0 |
|---|---|
| apple | mac_os_x · … → 10.4.11 |
| apple | mac_os_x · 10.5.0 → 10.5.8 |
| apple | mac_os_x · 10.6.0 → 10.6.2 |
| apple | mac_os_x_server · … → 10.4.11 |
| apple | mac_os_x_server · 10.5.0 → 10.5.8 |
| apple | mac_os_x_server · 10.6.0 → 10.6.2 |
| apple | safari · … → 4.0.4 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| fedoraproject | fedora |
| chrome · … → 2.0.172.43 | |
| opensuse | opensuse · 10.3 → 11.1 |
| redhat | enterprise_linux |
| sun | openoffice.org · 2.0.0 → 2.4.3 |
| sun | openoffice.org · 3.0.0 → 3.1.1 |
| suse | linux_enterprise |
| suse | linux_enterprise_server |
| vmware | esx |
| vmware | esxi |
| vmware | vcenter_server |
| vmware | vma |
| xmlsoft | libxml |
| xmlsoft | libxml2 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.