PT-2010-1009 · Xmlsoft+3 · Libxml2+3
Inferno
·
Published
2010-12-07
·
Updated
2024-06-15
·
CVE-2011-3905
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 versions prior to 2.7.7
libxml2 version 2.7.6
Description
The issue allows remote attackers to cause a denial of service or disrupt the confidentiality, integrity, and availability of protected information. This can be exploited via unspecified vectors, potentially leading to out-of-bounds read or other security breaches. The vulnerability can be exploited remotely.
Recommendations
For libxml2 version 2.7.6, consider updating to a newer version to mitigate the risk.
For libxml2 versions prior to 2.7.7, update to version 2.7.7 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Double Free
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Google Chrome
Red Hat
Libxml2