First published: Mon Aug 03 2009(Updated: )
A stack overflow flaw was found in libxml by parsing root XML document element DTD definition. Providing a specially-crafted XML file would lead to excessive stack growth and denial of service (application crash), when opened by a victim.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
libxml2 | =2.6.16 | |
libxml2 | =2.6.32 | |
libxml2 | =2.6.26 | |
libxml2 | =2.6.27 | |
Libxml2 | =1.8.17 | |
libxml2 | =2.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2414 has a severity level that may lead to a denial of service due to a stack overflow in libxml.
To fix CVE-2009-2414, upgrade libxml2 to version 2.6.33 or later.
CVE-2009-2414 affects libxml2 versions 2.5.10 through 2.6.32.
Yes, CVE-2009-2414 can be exploited remotely by sending a specially-crafted XML file.
CVE-2009-2414 can cause applications that use libxml2 to crash due to excessive stack growth.