PT-2010-1006 · Xmlsoft+3 · Libxml2+3
Yang Dingning
·
Published
2010-12-07
·
Updated
2020-05-19
·
CVE-2011-2821
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 versions prior to 2.7.8
Google Chrome versions prior to 13.0.782.215
Description
The issue is related to a double free vulnerability in libxml2, which can be exploited by remote attackers via a crafted XPath expression, potentially leading to a denial of service or other unspecified impacts. The vulnerability can be exploited remotely and may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations
For libxml2 versions prior to 2.7.8, update to version 2.7.8 or later to resolve the issue.
For Google Chrome versions prior to 13.0.782.215, update to version 13.0.782.215 or later to resolve the issue.
Exploit
Fix
DoS
Buffer Overflow
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Google Chrome
Red Hat
Libxml2