PT-2010-1061 · Xmlsoft+5 · Libxml2+5

Published

2010-12-07

·

Updated

2024-06-15

·

CVE-2011-3102

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.7.7 Google Chrome versions prior to 19.0.1084.46
Description The issue is caused by an off-by-one error in libxml2, which can be exploited by remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For libxml2 versions prior to 2.7.7, update to version 2.7.7 or later to resolve the issue. For Google Chrome versions prior to 19.0.1084.46, update to version 19.0.1084.46 or later to resolve the issue. As a temporary workaround, consider restricting access to the libxml2 library until a patch is available.

Fix

DoS

Buffer Overflow

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
CESA-2012_1288
CESA-2013_0217
CVE-2011-3102
DSA-2479-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:1288
RHSA-2012_1288
RHSA-2013:0217
RHSA-2013_0217
SUSE-SU-2012_0793-1
SUSE-SU-2013_1625-1
SUSE-SU-2013_1627-1

Affected Products

Centos
Google Chrome
Red Hat
Suse
Itunes
Libxml2