PT-2010-5670 · Xmlsoft+7 · Libxml2+7

Huzaifa S. Sidhpurwala

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2012-5134

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions prior to 2.9.1 libxml2-2 versions prior to 2.9.1 libxml2-2-32bit versions prior to 2.9.1 libxml2-32bit versions prior to 2.9.1 libxml2-devel versions prior to 2.9.1 libxml2-devel-32bit versions prior to 2.9.1 libxml2-doc versions prior to 2.9.1 libxml2-debuginfo versions prior to 2.9.1 libxml2-debuginfo-32bit versions prior to 2.9.1 libxml2-debuginfo-x86 versions prior to 2.9.1 libxml2-test versions prior to 2.9.1 libxml2-tools versions prior to 2.9.1 libxml2-tools-debuginfo versions prior to 2.9.1 libxml2-x86 versions prior to 2.9.1 mingw32-libxml2-2.7.6 mingw32-libxml2-static-2.7.6 mingw32-libxml2-debuginfo-2.7.6
Description The issue is related to a heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2, which can be exploited remotely. This can lead to a denial of service or possibly execute arbitrary code via crafted entities in an XML document. The vulnerability can be exploited to disrupt the confidentiality, integrity, and availability of protected information.
Recommendations For libxml2 versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-2 versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-2-32bit versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-32bit versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-devel versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-devel-32bit versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-doc versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-debuginfo versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-debuginfo-32bit versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-debuginfo-x86 versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-test versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-tools versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-tools-debuginfo versions prior to 2.9.1, update to version 2.9.1 or later. For libxml2-x86 versions prior to 2.9.1, update to version 2.9.1 or later. For mingw32-libxml2-2.7.6, update to a version that is not vulnerable. For mingw32-libxml2-static-2.7.6, update to a version that is not vulnerable. For mingw32-libxml2-debuginfo-2.7.6, update to a version that is not vulnerable.

Fix

DoS

Buffer Overflow

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2345
BDU:2015-04349
BDU:2015-04350
BDU:2015-04351
BDU:2015-04352
BDU:2015-04353
BDU:2015-04354
BDU:2015-04355
BDU:2015-05507
BDU:2015-05508
BDU:2015-05509
BDU:2015-05510
BDU:2015-05511
BDU:2015-05512
BDU:2015-05513
BDU:2015-05514
BDU:2015-05515
BDU:2015-05516
BDU:2015-05517
BDU:2015-05518
BDU:2015-05519
BDU:2015-05520
BDU:2015-05521
BDU:2015-05522
BDU:2015-05523
BDU:2015-05524
BDU:2015-05525
BDU:2015-05526
BDU:2015-05527
BDU:2015-06428
BDU:2015-06429
BDU:2015-06430
BDU:2015-08639
BDU:2015-08640
BDU:2015-08641
BDU:2015-09713
CESA-2012_1512
CESA-2013_0217
CVE-2012-5134
DSA-2580-1
OPENSUSE-SU-2012_1637-1
OPENSUSE-SU-2012_1647-1
OPENSUSE-SU-2013_0178-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:10192-1
OPENSUSE-SU-2024:10228-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:1512
RHSA-2012_1512
RHSA-2013:0217
RHSA-2013_0217
SUSE-SU-2012_1636-1

Affected Products

Alt Linux
Centos
Google Chrome
Junos
Red Hat
Suse
Itunes
Libxml2