PT-2010-1008 · Apple+3 · Safari+3
Billy Rios
·
Publicado
2010-12-07
·
Atualizado
2013-02-07
·
CVE-2011-0216
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Safari version 5.0.6 and earlier
libxml2 versions 2.7.6 and earlier
Description
The issue is related to an off-by-one error in libxml, which can lead to a heap-based buffer overflow and application crash, allowing remote attackers to execute arbitrary code or cause a denial of service. Multiple vulnerabilities in the libxml2 package can also lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For Apple Safari version 5.0.6 and earlier, update to version 5.0.6 or later to resolve the issue.
For libxml2 versions 2.7.6 and earlier, update to a version later than 2.7.6 to resolve the issue.
As a temporary workaround, consider restricting access to the libxml2 package to minimize the risk of exploitation.
Correção
DoS
RCE
Buffer Overflow
Double Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Safari
Libxml2