PT-2010-1062 · Mingw+6 · Mingw32-Libxml2-Debuginfo+8

Juraj Somorovsky

·

Published

2010-12-07

·

Updated

2023-02-13

·

CVE-2012-0841

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.8.0 mingw32-libxml2 versions 2.7.6 mingw32-libxml2-debuginfo versions 2.7.6 mingw32-libxml2-static versions 2.7.6
Description The issue concerns multiple vulnerabilities in the libxml2 package, which can lead to disruptions in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are related to the computation of hash values without restricting the ability to trigger hash collisions predictably, allowing context-dependent attackers to cause a denial of service via crafted XML data. Additionally, the vulnerabilities involve double-free memory issues.
Recommendations For libxml2 versions prior to 2.8.0, update to version 2.8.0 or later. For mingw32-libxml2 versions 2.7.6, consider disabling the use of crafted XML data until a patch is available. For mingw32-libxml2-debuginfo versions 2.7.6, restrict access to sensitive information until a patch is available. For mingw32-libxml2-static versions 2.7.6, avoid using the vulnerable package until a patch is available. As a temporary workaround, consider restricting remote access to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Double Free

Weakness Enumeration

Related Identifiers

BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
CESA-2012_0324
CESA-2013_0217
CVE-2012-0841
DSA-2417-1
RHSA-2012:0324
RHSA-2012_0324
RHSA-2013:0217
RHSA-2013_0217
SUSE-SU-2012_0626-1

Affected Products

Centos
Junos
Red Hat
Suse
Itunes
Libxml2
Mingw32-Libxml2
Mingw32-Libxml2-Debuginfo
Mingw32-Libxml2-Static