5
CVSSv2

CVE-2008-4409

Published: 03/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent malicious users to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2 2.7.1

xmlsoft libxml2 2.7.0

Exploits

source: wwwsecurityfocuscom/bid/31555/info The libxml2 library is prone to a denial-of-service vulnerability caused by an error when handling files using entities in entity definitions An attacker can exploit this issue to cause the library to consume an excessive amount of memory, denying service to legitimate users The issue affects ...