CVE-2009-2414
Published: 11 August 2009
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
Priority
Status
Package | Release | Status |
---|---|---|
libxml Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Released
(1:1.8.17-14.1ubuntu0.1)
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
upstream |
Needs triage
|
|
libxml2 Launchpad, Ubuntu, Debian |
dapper |
Released
(2.6.24.dfsg-1ubuntu1.5)
|
hardy |
Released
(2.6.31.dfsg-2ubuntu1.4)
|
|
intrepid |
Released
(2.6.32.dfsg-4ubuntu1.2)
|
|
jaunty |
Released
(2.6.32.dfsg-5ubuntu4.2)
|
|
karmic |
Not vulnerable
|
|
lucid |
Not vulnerable
|
|
upstream |
Released
(2.7.3.dfsg-2.1)
|