PT-2010-1010 · Xmlsoft+4 · Libxml2+4

Jüri Aedla

·

Published

2010-12-07

·

Updated

2024-06-15

·

CVE-2011-3919

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.7.7 Google Chrome versions prior to 16.0.912.75
Description The issue is related to a heap-based buffer overflow in libxml2, which can be exploited by remote attackers to cause a denial of service or possibly have other impacts. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For libxml2 versions prior to 2.7.7, update to version 2.7.7 or later to resolve the issue. For Google Chrome versions prior to 16.0.912.75, update to version 16.0.912.75 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Double Free

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01746
BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
CESA-2012_0018
CESA-2013_0217
CVE-2011-3919
DSA-2394-1
OPENSUSE-SU-2012_0107-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:0016
RHSA-2012:0017
RHSA-2012:0018
RHSA-2012:0104
RHSA-2012_0016
RHSA-2012_0017
RHSA-2012_0018
RHSA-2013:0217
RHSA-2013_0217
SUSE-SU-2012_0117-1

Affected Products

Centos
Google Chrome
Red Hat
Suse
Libxml2