Lucene search

K
cve[email protected]CVE-2009-2414
HistoryAug 11, 2009 - 6:30 p.m.

CVE-2009-2414

2009-08-1118:30:00
CWE-119
web.nvd.nist.gov
84
4
vulnerability
libxml2
denial of service
application crash
recursion
cve-2009-2414
nvd
codenomicon xml fuzzing framework

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

61.5%

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

Affected configurations

NVD
Node
xmlsoftlibxmlMatch1.8.17
OR
xmlsoftlibxml2Match2.5.10
OR
xmlsoftlibxml2Match2.6.16
OR
xmlsoftlibxml2Match2.6.26
OR
xmlsoftlibxml2Match2.6.27
OR
xmlsoftlibxml2Match2.6.32
VendorProductVersionCPE
xmlsoftlibxml22.5.10cpe:/a:xmlsoft:libxml2:2.5.10:::
xmlsoftlibxml22.6.27cpe:/a:xmlsoft:libxml2:2.6.27:::
xmlsoftlibxml22.6.16cpe:/a:xmlsoft:libxml2:2.6.16:::
xmlsoftlibxml1.8.17cpe:/a:xmlsoft:libxml:1.8.17:::
xmlsoftlibxml22.6.26cpe:/a:xmlsoft:libxml2:2.6.26:::
xmlsoftlibxml22.6.32cpe:/a:xmlsoft:libxml2:2.6.32:::

References

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.002

Percentile

61.5%