Rauli Kaksonen, Tero Rontti and Jukka Taimisto discovered several
vulnerabilities in libxml2, a library for parsing and handling XML data
files, which can lead to denial of service conditions or possibly arbitrary
code execution in the application using the library. The Common
Vulnerabilities and Exposures project identifies the following problems:
An XML document with specially-crafted Notation or Enumeration attribute
types in a DTD definition leads to the use of a pointers to memory areas
which have already been freed (CVE-2009-2416).
Missing checks for the depth of ELEMENT DTD definitions when parsing
child content can lead to extensive stack-growth due to a function
recursion which can be triggered via a crafted XML document (CVE-2009-2414).
For the oldstable distribution (etch), this problem has been fixed in
version 2.6.27.dfsg-6+etch1.
For the stable distribution (lenny), this problem has been fixed in
version 2.6.32.dfsg-5+lenny1.
For the testing (squeeze) and unstable (sid) distribution...
Get the latest Linux and open source security news straight to your inbox.