Description
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
Published: 2009-08-11
Score: 4.3 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1859-1 New libxml2 packages fix several issues
Debian DSA Debian DSA DSA-1861-1 New libxml packages fix several issues
EUVD EUVD EUVD-2009-2410 Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
Ubuntu USN Ubuntu USN USN-815-1 libxml2 vulnerabilities
References
Link Providers
http://googlechromereleases.blogspot.com/2009/08/stable-update-security-fixes.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html cve-icon cve-icon
http://secunia.com/advisories/35036 cve-icon cve-icon
http://secunia.com/advisories/36207 cve-icon cve-icon
http://secunia.com/advisories/36338 cve-icon cve-icon
http://secunia.com/advisories/36417 cve-icon cve-icon
http://secunia.com/advisories/36631 cve-icon cve-icon
http://secunia.com/advisories/37346 cve-icon cve-icon
http://secunia.com/advisories/37471 cve-icon cve-icon
http://support.apple.com/kb/HT3937 cve-icon cve-icon
http://support.apple.com/kb/HT3949 cve-icon cve-icon
http://support.apple.com/kb/HT4225 cve-icon cve-icon
http://www.cert.fi/en/reports/2009/vulnerability2009085.html cve-icon cve-icon
http://www.codenomicon.com/labs/xml/ cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1859 cve-icon cve-icon
http://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg678527.html cve-icon cve-icon
http://www.networkworld.com/columnists/2009/080509-xml-flaw.html cve-icon cve-icon
http://www.openoffice.org/security/cves/CVE-2009-2414-2416.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/36010 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-815-1 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/2420 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3184 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3217 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=515195 cve-icon cve-icon
https://git.gnome.org/browse/libxml2/commit/?id=489f9671e71cc44a97b23111b3126ac8a1e21a59 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-2414 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10129 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8639 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-2414 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00537.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00547.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00642.html cve-icon cve-icon
History

No history.

Subscriptions

Redhat Enterprise Linux
Xmlsoft Libxml Libxml2
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T05:52:14.941Z

Reserved: 2009-07-09T00:00:00.000Z

Link: CVE-2009-2414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-08-11T18:30:00.937

Modified: 2026-04-23T00:35:47.467

Link: CVE-2009-2414

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-08-10T00:00:00Z

Links: CVE-2009-2414 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses