PT-2012-1040 · Xmlsoft+6 · Libxml2+6

Chris Evans

·

Published

2012-08-30

·

Updated

2024-06-15

·

CVE-2012-2871

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.9.0-rc1 and earlier Google Chrome versions prior to 21.0.1180.89
Description The issue is related to the handling of XSL transforms and the xmlNs data structure in include/libxml/tree.h. It allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document. Multiple vulnerabilities in the libxml2 package can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For libxml2 versions 2.9.0-rc1 and earlier, update to version 2.9.1 or later to resolve the issue. For Google Chrome versions prior to 21.0.1180.89, update to version 21.0.1180.89 or later to resolve the issue. As a temporary workaround, consider restricting the use of XSL transforms in libxml2 until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2345
BDU:2015-02885
BDU:2015-09713
CESA-2012_1265
CVE-2012-2871
DSA-2555-1
OPENSUSE-SU-2012_1215-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2012:1265
RHSA-2012_1265

Affected Products

Alt Linux
Centos
Google Chrome
Red Hat
Suse
Itunes
Libxml2