English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sun libxml2 DTD Parsing Denial of Service Vulnerabilities


Secunia ID

SA36631

CVE-ID

CVE-2009-2414, CVE-2009-2416

Release Date

07 Sep 2009

Last Change

30 Sep 2009

Criticality

Moderately Critical

Solution Status

Vendor Patch

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

Sun has acknowledged some vulnerabilities in libxml2 in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service).

For more information:
SA36207

Solution

Apply patches.

-- SPARC Platform --

Solaris 9:
Apply patch 114014-23 or later.

Solaris 10:
Apply patch 125731-05 or later.

OpenSolaris:
Fixed in builds snv_123 or later.

-- x86 Platform --

Solaris 9:
Apply patch 114015-23 or later.

Solaris 10:
Apply patch 125732-05 or later.

OpenSolaris:
Fixed in builds snv_123 or later.

Original Advisory

http://sunsolve.sun.com/search/document.do?assetkey=1-66-266688-1