CVE-2009-2414
CVE-2009-2414
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://googlechromereleases.blogspot.com/2009/08/stable-update-security-fixes.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=515195http://secunia.com/advisories/35036http://secunia.com/advisories/36207http://secunia.com/advisories/36338http://secunia.com/advisories/36417http://secunia.com/advisories/36631http://secunia.com/advisories/37346