PT-2010-5637 · Mingw+4 · Mingw32-Libxml2-Debuginfo+9

Bui Quang Minh

·

Published

1970-01-01

·

Updated

2020-06-04

·

CVE-2010-4008

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.7.8 libxml2-dev (affected versions not specified) libxml2-doc (affected versions not specified) libxml2-utils (affected versions not specified) mingw32-libxml2-2.7.6 mingw32-libxml2-static-2.7.6 mingw32-libxml2-debuginfo-2.7.6
Description The issue is related to multiple vulnerabilities in the libxml2 library, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. The vulnerabilities are associated with reading from invalid memory locations during the processing of malformed XPath expressions, allowing context-dependent attackers to cause a denial of service (application crash) via a crafted XML document. The vulnerabilities can also be related to the repeated release of memory, allowing a remote attacker to disrupt confidentiality, integrity, and availability of protected information.
Recommendations For libxml2 versions prior to 2.7.8, update to version 2.7.8 or later. For libxml2-dev, libxml2-doc, and libxml2-utils, there is no information about a newer version that contains a fix for this vulnerability. For mingw32-libxml2-2.7.6, mingw32-libxml2-static-2.7.6, and mingw32-libxml2-debuginfo-2.7.6, consider disabling the use of the libxml2 library until a patch is available. As a temporary workaround, consider restricting access to the vulnerable library to minimize the risk of exploitation.

Exploit

DoS

Buffer Overflow

Double Free

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01771
BDU:2015-01772
BDU:2015-01773
BDU:2015-01774
BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
BDU:2015-09421
CESA-2013_0217
CVE-2010-4008
DSA-2128-1
RHSA-2011:1749
RHSA-2011_1749
RHSA-2012:0017
RHSA-2012_0017
RHSA-2013:0217
RHSA-2013_0217

Affected Products

Centos
Openoffice
Red Hat
Libxml2
Libxml2-Devel
Libxml2-Doc
Libxml2-Utils
Mingw32-Libxml2
Mingw32-Libxml2-Debuginfo
Mingw32-Libxml2-Static