PT-2010-1062 · Mingw+6 · Mingw32-Libxml2-Debuginfo+8

·

CVE-2012-0841

·

Publicado

2010-12-07

·

Atualizado

2023-02-13

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.8.0 mingw32-libxml2 versions 2.7.6 mingw32-libxml2-debuginfo versions 2.7.6 mingw32-libxml2-static versions 2.7.6
Description The issue concerns multiple vulnerabilities in the libxml2 package, which can lead to disruptions in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are related to the computation of hash values without restricting the ability to trigger hash collisions predictably, allowing context-dependent attackers to cause a denial of service via crafted XML data. Additionally, the vulnerabilities involve double-free memory issues.
Recommendations For libxml2 versions prior to 2.8.0, update to version 2.8.0 or later. For mingw32-libxml2 versions 2.7.6, consider disabling the use of crafted XML data until a patch is available. For mingw32-libxml2-debuginfo versions 2.7.6, restrict access to sensitive information until a patch is available. For mingw32-libxml2-static versions 2.7.6, avoid using the vulnerable package until a patch is available. As a temporary workaround, consider restricting remote access to minimize the risk of exploitation.

Correção

DoS

Buffer Overflow

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
CESA-2012_0324
CESA-2013_0217
CVE-2012-0841
DSA-2417-1
RHSA-2012:0324
RHSA-2012_0324
RHSA-2013:0217
RHSA-2013_0217
SUSE-SU-2012_0626-1

Produtos afetados

Centos
Junos
Red Hat
Suse
Itunes
Libxml2
Mingw32-Libxml2
Mingw32-Libxml2-Debuginfo
Mingw32-Libxml2-Static