CVE-2009-2416
Last modified
CVE-2009-2416 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml | 1.8.17 |
| Xmlsoft | Libxml2 | 2.5.10 |
| Xmlsoft | Libxml2 | 2.6.16 |
| Xmlsoft | Libxml2 | 2.6.26 |
| Xmlsoft | Libxml2 | 2.6.27 |
| Xmlsoft | Libxml2 | 2.6.32 |
| Fedoraproject | Fedora | 10 |
| Fedoraproject | Fedora | 11 |
| Debian | Debian Linux | 4.0 |
| Redhat | Enterprise Linux | 3.0 |
| Redhat | Enterprise Linux | 4.0 |
| Redhat | Enterprise Linux | 5.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 8.10 |
| Canonical | Ubuntu Linux | 9.04 |
| Chrome | < 2.0.172.43 | |
| Apple | Safari | < 4.0.4 |
| Apple | Iphone Os | >= 2.0, < 4.0 |
| Apple | Mac Os X | < 10.4.11 |
| Apple | Mac Os X | >= 10.5.0, < 10.5.8 |
| Apple | Mac Os X | >= 10.6.0, < 10.6.2 |
| Apple | Mac Os X Server | < 10.4.11 |
| Apple | Mac Os X Server | >= 10.5.0, < 10.5.8 |
| Apple | Mac Os X Server | >= 10.6.0, < 10.6.2 |
| Opensuse | Opensuse | >= 10.3, <= 11.1 |
| Suse | Linux Enterprise | 10.0 |
| Suse | Linux Enterprise | 11.0 |
| Suse | Linux Enterprise Server | 9 |
| Vmware | Vcenter Server | 4.0 |
| Vmware | Vma | 4.0 |
| Vmware | Esx | 3.0.3 |
| Vmware | Esx | 3.5 |
| Vmware | Esx | 4.0 |
| Vmware | Esxi | 3.5 |
| Vmware | Esxi | 4.0 |
| Sun | Openoffice.Org | >= 2.0.0, < 2.4.3 |
| Sun | Openoffice.Org | >= 3.0.0, < 3.1.1 |
References
- https://secunia.com/advisories/35036Broken Link
- https://secunia.com/advisories/36207Broken Link
- https://secunia.com/advisories/36338Broken Link
- https://secunia.com/advisories/36417Broken Link
- https://secunia.com/advisories/36631Broken Link
- https://secunia.com/advisories/37346Broken Link
- https://secunia.com/advisories/37471Broken Link
- https://support.apple.com/kb/HT3937Third Party Advisory
- https://support.apple.com/kb/HT3949Third Party Advisory
- https://support.apple.com/kb/HT4225Third Party Advisory
- https://www.codenomicon.com/labs/xml/Broken Link
- https://www.debian.org/security/2009/dsa-1859Mailing List, Patch
- https://www.openoffice.org/security/cves/CVE-2009-2414-2416.htmlThird Party Advisory
- https://www.securityfocus.com/archive/1/507985/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/36010Broken Link, Third Party Advisory, VDB Entry
- https://www.ubuntu.com/usn/USN-815-1Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515205Issue Tracking, Patch
- https://secunia.com/advisories/35036Broken Link
- https://secunia.com/advisories/36207Broken Link
- https://secunia.com/advisories/36338Broken Link
- https://secunia.com/advisories/36417Broken Link
- https://secunia.com/advisories/36631Broken Link
- https://secunia.com/advisories/37346Broken Link
- https://secunia.com/advisories/37471Broken Link
- https://support.apple.com/kb/HT3937Third Party Advisory
- https://support.apple.com/kb/HT3949Third Party Advisory
- https://support.apple.com/kb/HT4225Third Party Advisory
- https://www.codenomicon.com/labs/xml/Broken Link
- https://www.debian.org/security/2009/dsa-1859Mailing List, Patch
- https://www.openoffice.org/security/cves/CVE-2009-2414-2416.htmlThird Party Advisory
- https://www.securityfocus.com/archive/1/507985/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/36010Broken Link, Third Party Advisory, VDB Entry
- https://www.ubuntu.com/usn/USN-815-1Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=515205Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2416?
How severe is CVE-2009-2416?
How do I fix CVE-2009-2416?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-2410The local_handler_callback function in server/responder/pam/…
- CVE-2009-2411Multiple integer overflows in the libsvn_delta library in Su…
- CVE-2009-2412Multiple integer overflows in the Apache Portable Runtime (A…
- CVE-2009-2413Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-2414Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2…
- CVE-2009-2415Multiple integer overflows in memcached 1.1.12 and 1.2.2 all…
- CVE-2009-2417lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when Op…
- CVE-2009-2418Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-2419Use-after-free vulnerability in the servePendingRequests fun…
- CVE-2009-2420Apple Safari 3.2.3 does not properly implement the file: pro…
- CVE-2009-2421The CFCharacterSetInitInlineBuffer method in CoreFoundation.…
- CVE-2009-2422The example code for the digest authentication functionality…9.8
Are you affected by CVE-2009-2416?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
