Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Aug 11, 2009 |
| Apple Osx Libxml | — | Upgrade macOS to the latest versionApply OS X security update 2009-006 | Dec 16, 2011 | Aug 11, 2009 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 4.0.4 | Jan 5, 2012 | Aug 11, 2009 |
| Centos_linux | — | Upgrade libxml-develUpgrade libxmlUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-python | Dec 1, 2016 | Aug 11, 2009 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Aug 11, 2009 |
| Freebsd | — | Upgrade libxml | Dec 10, 2025 | Nov 10, 2011 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Aug 11, 2009 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Oct 16, 2024 | Aug 11, 2009 |
| Suse | — | Upgrade libxml2-32bitUpgrade libxml-develUpgrade libxml2-docUpgrade libxml-32bitUpgrade libxmlUpgrade libxml2Upgrade libxml2-x86Upgrade libxml2-develUpgrade libxml2-devel-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Aug 11, 2009 |
| Vmsa 2009 0016 5 Updated Service Console Package Libxml2 | — | Upgrade VMware ESX 3.5 to build number 226117Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Aug 11, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub