CVE-2009-2416: Use After Free
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Other sources
Pointer use-after-free flaws were found in libxml by parsing Notation and Enumeration attribute types. A remote attacker could provide a specially-crafted XML file, which once opened by a local, unsuspecting user would lead to denial of service (application crash).
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2416?
CVE-2009-2416 is considered a medium severity vulnerability due to its potential to cause denial of service through application crashes.
How do I fix CVE-2009-2416?
To fix CVE-2009-2416, upgrade to a version of libxml2 that is newer than 2.6.32.
What software is affected by CVE-2009-2416?
CVE-2009-2416 affects multiple versions of libxml2 including 2.5.10 through 2.6.32 and libxml 1.8.17.
What type of vulnerability is CVE-2009-2416?
CVE-2009-2416 is classified as a use-after-free vulnerability.
What impact can CVE-2009-2416 have on applications?
CVE-2009-2416 can lead to application crashes, resulting in denial of service for users.