CVE-2009-2414
libxml - several issues
EPSS 3.1%
描述
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
如何修補 CVE-2009-2414
要修補 CVE-2009-2414,請將受影響套件升級到下列已修補版本。
- Debian/libxml—升級至 1:1.8.17-14+etch1 或更新版本
- Debian/libxml2—升級至 2.7.3.dfsg-2.1 或更新版本
- —升級至 2.6.27.dfsg-6+etch1 或更新版本
CVE-2009-2414 正在被利用嗎?
低 — EPSS 為 3.1%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 1:1.8.17-14+etch1
- from 0, < 2.7.3.dfsg-2.1
- from 0, < 2.6.27.dfsg-6+etch1