The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

vulnerability CVE-2009-2414 CVE-2009-2416

libxml, libxml2: denials of service

Synthesis of the vulnerability

An attacker can create malformed XML data, in order to generate a denial of service in applications linked to libxml.
Vulnerable systems: Debian, Fedora, libxml, Mandriva Linux, Windows (platform) ~ not comprehensive, NLD, OES, OpenSolaris, openSUSE, Solaris, Trusted Solaris, RHEL, SLES, Unix (platform) ~ not comprehensive, ESX, ESXi, VMware Server, vCenter Server, VirtualCenter.
Severity of this threat: 2/4.
Consequences of a hack: denial of service on service, denial of service on client.
Pirate's origin: document.
Number of vulnerabilities in this bulletin: 2.
Creation date: 11/08/2009.
Références of this weakness: 266088, 266688, 6872373, 6872499, BID-36010, CERTA-2009-AVI-335, CVE-2009-2414, CVE-2009-2416, DSA-1859-1, DSA-1861-1, FEDORA-2009-8491, FEDORA-2009-8498, FEDORA-2009-8580, FEDORA-2009-8582, FEDORA-2009-8594, FICORA #245608, MDVSA-2009:200, MDVSA-2009:200-1, RHSA-2009:1206-01, SUSE-SR:2009:013, SUSE-SR:2009:015, VIGILANCE-VUL-8930, VMSA-2009-0016, VMSA-2009-0016.1, VMSA-2009-0016.2, VMSA-2009-0016.3, VMSA-2009-0016.4, VMSA-2009-0016.5.

Description of the vulnerability

The libxml/libxml2 library implements a XML parser. It is impacted by two vulnerabilities.

A malicious DTD document generates an infinite recursion, which fills the stack, and stop the application. This vulnerability is different from VIGILANCE-VUL-8926. [severity:2/4; CERTA-2009-AVI-335, CVE-2009-2414]

An XML document, containing Notation and Enumeration attribute types, forces the usage of freed memory, which stops the application. [severity:2/4; CVE-2009-2416]

An attacker can therefore create malformed XML data, in order to generate a denial of service in applications linked to libxml.
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides computer vulnerability analysis. Each administrator can customize the list of products for which he wants to receive vulnerability alerts. The Vigil@nce vulnerability database contains several thousand vulnerabilities. The technology watch team tracks security threats targeting the computer system.