PT-2012-1040 · Xmlsoft+6 · Libxml2+6

Chris Evans

·

Publicado

2012-08-30

·

Atualizado

2024-06-15

·

CVE-2012-2871

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.9.0-rc1 and earlier Google Chrome versions prior to 21.0.1180.89
Description The issue is related to the handling of XSL transforms and the xmlNs data structure in include/libxml/tree.h. It allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document. Multiple vulnerabilities in the libxml2 package can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For libxml2 versions 2.9.0-rc1 and earlier, update to version 2.9.1 or later to resolve the issue. For Google Chrome versions prior to 21.0.1180.89, update to version 21.0.1180.89 or later to resolve the issue. As a temporary workaround, consider restricting the use of XSL transforms in libxml2 until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2345
BDU:2015-02885
BDU:2015-09713
CESA-2012_1265
CVE-2012-2871
DSA-2555-1
OPENSUSE-SU-2012_1215-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:1265
RHSA-2012_1265

Produtos afetados

Alt Linux
Centos
Google Chrome
Red Hat
Suse
Itunes
Libxml2