First published: Wed Jun 01 2011(Updated: )
An integer overflow, leading to heap-based buffer overflow was found in the way libxml, XML files manipulation library, processed certain XPath expressions. A remote attacker could provide a specially-crafted XML file, which once opened in an application linked against libxml would cause that application to crash, or, potentially, execute arbitrary code with the privileges of the user running the application. References: [1] <a href="http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html">http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html</a> [2] <a href="http://www.openwall.com/lists/oss-security/2011/05/31/5">http://www.openwall.com/lists/oss-security/2011/05/31/5</a> [3] <a href="http://www.openwall.com/lists/oss-security/2011/05/31/8">http://www.openwall.com/lists/oss-security/2011/05/31/8</a> Upstream patch: [4] <a href="http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4">http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xmlsoft Libxml2 | =2.6.16 | |
Xmlsoft Libxml2 | =2.6.32 | |
Xmlsoft Libxml2 | =2.6.26 | |
Xmlsoft Libxml2 | =2.6.11 | |
Xmlsoft Libxml2 | =2.6.17 | |
Xmlsoft Libxml2 | =2.6.27 | |
Xmlsoft Libxml2 | =2.6.13 | |
Xmlsoft Libxml2 | =2.6.7 | |
Xmlsoft Libxml2 | =2.6.14 | |
Xmlsoft Libxml2 | =2.6.8 | |
Xmlsoft Libxml2 | =2.6.2 | |
Xmlsoft Libxml2 | =2.6.5 | |
Xmlsoft Libxml2 | =2.6.4 | |
Xmlsoft Libxml2 | =2.6.18 | |
Xmlsoft Libxml2 | =2.6.1 | |
Xmlsoft Libxml2 | =2.6.20 | |
Xmlsoft Libxml2 | =2.6.12 | |
Xmlsoft Libxml2 | =2.6.0 | |
Xmlsoft Libxml2 | =2.6.9 | |
Xmlsoft Libxml2 | =2.6.30 | |
Xmlsoft Libxml2 | =2.6.22 | |
Xmlsoft Libxml2 | =2.6.3 | |
Xmlsoft Libxml2 | =2.6.6 | |
Xmlsoft Libxml2 | =2.7.2 | |
Xmlsoft Libxml2 | =2.7.8 | |
Xmlsoft Libxml2 | =2.7.7 | |
Xmlsoft Libxml2 | =2.7.5 | |
Xmlsoft Libxml2 | =2.7.3 | |
Xmlsoft Libxml2 | =2.7.1 | |
Xmlsoft Libxml2 | =2.7.0 | |
Xmlsoft Libxml2 | =2.7.6 | |
Xmlsoft Libxml2 | =2.7.4 | |
XMLSoft Libxml | =1.8.9 | |
XMLSoft Libxml | =1.6.0 | |
XMLSoft Libxml | =1.7.2 | |
XMLSoft Libxml | =1.8.3 | |
XMLSoft Libxml | =1.8.0 | |
XMLSoft Libxml | =1.8.13 | |
XMLSoft Libxml | =1.8.10 | |
XMLSoft Libxml | =1.8.4 | |
XMLSoft Libxml | =1.8.6 | |
XMLSoft Libxml | =1.7.0 | |
XMLSoft Libxml | <=1.8.16 | |
XMLSoft Libxml | =1.8.14 | |
XMLSoft Libxml | =1.8.8 | |
XMLSoft Libxml | =1.7.4 | |
XMLSoft Libxml | =1.8.7 | |
XMLSoft Libxml | =1.7.3 | |
XMLSoft Libxml | =1.8.1 | |
XMLSoft Libxml | =1.8.11 | |
XMLSoft Libxml | =1.6.2 | |
XMLSoft Libxml | =1.5.0 | |
XMLSoft Libxml | =1.8.2 | |
XMLSoft Libxml | =1.8.12 | |
XMLSoft Libxml | =1.8.5 | |
XMLSoft Libxml | =1.6.1 | |
XMLSoft Libxml | =1.8.15 | |
XMLSoft Libxml | =1.7.1 | |
redhat/libxml2 | <2.8.0 | 2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.