PT-2010-1060 · Xmlsoft+4 · Libxml2+4

Yang Dingning

·

Publicado

2010-12-07

·

Atualizado

2024-06-15

·

CVE-2010-4494

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.7.6 through 2.7.8 mingw32-libxml2 versions 2.7.6 mingw32-libxml2-debuginfo versions 2.7.6 mingw32-libxml2-static versions 2.7.6 Google Chrome version prior to 8.0.552.215
Description The issue is related to multiple vulnerabilities in the libxml2 package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A double free vulnerability in libxml2, as used in Google Chrome, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Recommendations For libxml2 versions 2.7.6 through 2.7.8, update to a version later than 2.7.8 to resolve the issue. For mingw32-libxml2, mingw32-libxml2-debuginfo, and mingw32-libxml2-static versions 2.7.6, update to a version later than 2.7.6 to resolve the issue. For Google Chrome version prior to 8.0.552.215, update to version 8.0.552.215 or later to resolve the issue. As a temporary workaround, consider restricting access to the XPath handling functionality until a patch is available.

Exploit

Correção

DoS

Buffer Overflow

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
CESA-2013_0217
CVE-2010-4494
DSA-2137-1
OPENSUSE-SU-2024:10192-1
RHSA-2011:1749
RHSA-2011_1749
RHSA-2013:0217
RHSA-2013_0217

Produtos afetados

Centos
Google Chrome
Openoffice
Red Hat
Libxml2