Medium severity6.5NVD Advisory· Published Aug 11, 2009· Updated Apr 23, 2026
CVE-2009-2416
CVE-2009-2416
Description
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Affected products
33- cpe:2.3:a:vmware:vcenter_server:4.0:-:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.16:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.26:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.27:*:*:*:*:*:*:*
- cpe:2.3:a:xmlsoft:libxml2:2.6.32:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
36- www.debian.org/security/2009/dsa-1859nvdMailing ListPatch
- www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg678527.htmlnvdPatch
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- git.gnome.org/browse/libxml2/commit/nvdPatch
- support.apple.com/kb/HT3937nvdThird Party Advisory
- support.apple.com/kb/HT3949nvdThird Party Advisory
- support.apple.com/kb/HT4225nvdThird Party Advisory
- www.openoffice.org/security/cves/CVE-2009-2414-2416.htmlnvdThird Party Advisory
- www.securityfocus.com/archive/1/507985/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/36010nvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-815-1nvdThird Party Advisory
- www.vmware.com/security/advisories/VMSA-2009-0016.htmlnvdThird Party Advisory
- googlechromereleases.blogspot.com/2009/08/stable-update-security-fixes.htmlnvdRelease Notes
- lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlnvdMailing List
- lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlnvdMailing List
- lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlnvdMailing List
- lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.htmlnvdMailing List
- secunia.com/advisories/35036nvdBroken Link
- secunia.com/advisories/36207nvdBroken Link
- secunia.com/advisories/36338nvdBroken Link
- secunia.com/advisories/36417nvdBroken Link
- secunia.com/advisories/36631nvdBroken Link
- secunia.com/advisories/37346nvdBroken Link
- secunia.com/advisories/37471nvdBroken Link
- www.cert.fi/en/reports/2009/vulnerability2009085.htmlnvdBroken Link
- www.codenomicon.com/labs/xml/nvdBroken Link
- www.networkworld.com/columnists/2009/080509-xml-flaw.htmlnvdBroken Link
- www.vupen.com/english/advisories/2009/2420nvdBroken Link
- www.vupen.com/english/advisories/2009/3184nvdBroken Link
- www.vupen.com/english/advisories/2009/3217nvdBroken Link
- www.vupen.com/english/advisories/2009/3316nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7783nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9262nvdBroken Link
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00537.htmlnvdMailing List
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00547.htmlnvdMailing List
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00642.htmlnvdMailing List
News mentions
0No linked articles in our index yet.