CVE-2009-2414
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
- Xmlsoft Libxml
- = 1.8.17
- Xmlsoft libxml2
- = 2.5.10, 2.6.16, 2.6.26, 2.6.27, 2.6.32
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 3.1% (87th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2009-08-11
CVE-2009-2414 at NVD
2 known exploits for CVE-2009-2414
Proof-of-concept code and exploit modules indexed by Sploitus