First published: Tue Dec 07 2010(Updated: )
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <8.0.552.215 | |
libxml2-devel | <=2.7.8 | |
Apple iOS and macOS | <10.6.7 | |
iTunes | <10.2 | |
Safari | <5.0.4 | |
iPhone OS | <4.3.0 | |
openSUSE | =11.2 | |
openSUSE | =11.3 | |
SUSE Linux Enterprise Server | =11-sp1 | |
Red Hat Fedora | =14 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Server EUS | =6.3 | |
Debian Linux | =5.0 | |
Debian Linux | =6.0 | |
HP Insight Control Server Deployment | ||
HP Rapid Deployment Pack | ||
Apache OpenOffice | >=3.0.0<3.3.0 | |
Apache OpenOffice | >=2.1.0<=2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4494 has a severity that can potentially lead to denial of service or unspecified impacts.
To fix CVE-2010-4494, users should upgrade to a version of impacted software that is beyond the vulnerable versions mentioned.
CVE-2010-4494 affects various products including Google Chrome before version 8.0.552.215 and libxml2 up to version 2.7.8.
CVE-2010-4494 can be exploited through vectors related to XPath handling, leading to potential crashes.
Yes, CVE-2010-4494 is a recognized security vulnerability reported in multiple widely used applications.