CVE-2012-0841: Medium severity libxml2-devel vulnerability
Published Dec 21, 2012
·Updated
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
Affected Software
172 affected components
XMLSoft Libxml2<=2.7.8
XMLSoft Libxml2=1.7.0
XMLSoft Libxml2=1.7.1
XMLSoft Libxml2=1.7.2
XMLSoft Libxml2=1.7.3
XMLSoft Libxml2=1.7.4
XMLSoft Libxml2=1.8.0
XMLSoft Libxml2=1.8.1
XMLSoft Libxml2=1.8.2
XMLSoft Libxml2=1.8.3
XMLSoft Libxml2=1.8.4
XMLSoft Libxml2=1.8.5
XMLSoft Libxml2=1.8.6
XMLSoft Libxml2=1.8.7
XMLSoft Libxml2=1.8.9
XMLSoft Libxml2=1.8.10
XMLSoft Libxml2=1.8.13
XMLSoft Libxml2=1.8.14
XMLSoft Libxml2=1.8.16
XMLSoft Libxml2=2.0.0
XMLSoft Libxml2=2.1.0
XMLSoft Libxml2=2.1.1
XMLSoft Libxml2=2.2.0
XMLSoft Libxml2=2.2.0-beta
XMLSoft Libxml2=2.2.1
XMLSoft Libxml2=2.2.2
XMLSoft Libxml2=2.2.3
XMLSoft Libxml2=2.2.4
XMLSoft Libxml2=2.2.5
XMLSoft Libxml2=2.2.6
XMLSoft Libxml2=2.2.7
XMLSoft Libxml2=2.2.8
XMLSoft Libxml2=2.2.9
XMLSoft Libxml2=2.2.10
XMLSoft Libxml2=2.2.11
XMLSoft Libxml2=2.3.0
XMLSoft Libxml2=2.3.1
XMLSoft Libxml2=2.3.2
XMLSoft Libxml2=2.3.3
XMLSoft Libxml2=2.3.4
XMLSoft Libxml2=2.3.5
XMLSoft Libxml2=2.3.6
XMLSoft Libxml2=2.3.7
XMLSoft Libxml2=2.3.8
XMLSoft Libxml2=2.3.9
XMLSoft Libxml2=2.3.10
XMLSoft Libxml2=2.3.11
XMLSoft Libxml2=2.3.12
XMLSoft Libxml2=2.3.13
XMLSoft Libxml2=2.3.14
XMLSoft Libxml2=2.4.1
XMLSoft Libxml2=2.4.2
XMLSoft Libxml2=2.4.3
XMLSoft Libxml2=2.4.4
XMLSoft Libxml2=2.4.5
XMLSoft Libxml2=2.4.6
XMLSoft Libxml2=2.4.7
XMLSoft Libxml2=2.4.8
XMLSoft Libxml2=2.4.9
XMLSoft Libxml2=2.4.10
XMLSoft Libxml2=2.4.11
XMLSoft Libxml2=2.4.12
XMLSoft Libxml2=2.4.13
XMLSoft Libxml2=2.4.14
XMLSoft Libxml2=2.4.15
XMLSoft Libxml2=2.4.16
XMLSoft Libxml2=2.4.17
XMLSoft Libxml2=2.4.18
XMLSoft Libxml2=2.4.19
XMLSoft Libxml2=2.4.20
XMLSoft Libxml2=2.4.21
XMLSoft Libxml2=2.4.22
XMLSoft Libxml2=2.4.23
XMLSoft Libxml2=2.4.24
XMLSoft Libxml2=2.4.25
XMLSoft Libxml2=2.4.26
XMLSoft Libxml2=2.4.27
XMLSoft Libxml2=2.4.28
XMLSoft Libxml2=2.4.29
XMLSoft Libxml2=2.4.30
XMLSoft Libxml2=2.5.0
XMLSoft Libxml2=2.5.4
XMLSoft Libxml2=2.5.7
XMLSoft Libxml2=2.5.8
XMLSoft Libxml2=2.5.10
XMLSoft Libxml2=2.5.11
XMLSoft Libxml2=2.6.0
XMLSoft Libxml2=2.6.1
XMLSoft Libxml2=2.6.2
XMLSoft Libxml2=2.6.3
XMLSoft Libxml2=2.6.4
XMLSoft Libxml2=2.6.5
XMLSoft Libxml2=2.6.6
XMLSoft Libxml2=2.6.7
XMLSoft Libxml2=2.6.8
XMLSoft Libxml2=2.6.9
XMLSoft Libxml2=2.6.11
XMLSoft Libxml2=2.6.12
XMLSoft Libxml2=2.6.13
XMLSoft Libxml2=2.6.14
XMLSoft Libxml2=2.6.16
XMLSoft Libxml2=2.6.17
XMLSoft Libxml2=2.6.18
XMLSoft Libxml2=2.6.20
XMLSoft Libxml2=2.6.21
XMLSoft Libxml2=2.6.22
XMLSoft Libxml2=2.6.23
XMLSoft Libxml2=2.6.24
XMLSoft Libxml2=2.6.25
XMLSoft Libxml2=2.6.26
XMLSoft Libxml2=2.6.27
XMLSoft Libxml2=2.6.28
XMLSoft Libxml2=2.6.29
XMLSoft Libxml2=2.6.30
XMLSoft Libxml2=2.6.31
XMLSoft Libxml2=2.6.32
XMLSoft Libxml2=2.7.0
XMLSoft Libxml2=2.7.1
XMLSoft Libxml2=2.7.2
XMLSoft Libxml2=2.7.3
XMLSoft Libxml2=2.7.4
XMLSoft Libxml2=2.7.5
XMLSoft Libxml2=2.7.6
XMLSoft Libxml2=2.7.7
Apple iPhone OS<=6.1.4
Apple iPhone OS=1.0.0
Apple iPhone OS=1.0.1
Apple iPhone OS=1.0.2
Apple iPhone OS=1.1.0
Apple iPhone OS=1.1.1
Apple iPhone OS=1.1.2
Apple iPhone OS=1.1.3
Apple iPhone OS=1.1.4
Apple iPhone OS=1.1.5
Apple iPhone OS=2.0
Apple iPhone OS=2.0.0
Apple iPhone OS=2.0.1
Apple iPhone OS=2.0.2
Apple iPhone OS=2.1
Apple iPhone OS=2.1.1
Apple iPhone OS=2.2
Apple iPhone OS=2.2.1
Apple iPhone OS=3.0
Apple iPhone OS=3.0.1
Apple iPhone OS=3.1
Apple iPhone OS=3.1.2
Apple iPhone OS=3.1.3
Apple iPhone OS=3.2
Apple iPhone OS=3.2.1
Apple iPhone OS=3.2.2
Apple iPhone OS=4.0
Apple iPhone OS=4.0.1
Apple iPhone OS=4.0.2
Apple iPhone OS=4.1
Apple iPhone OS=4.2.1
Apple iPhone OS=4.2.5
Apple iPhone OS=4.2.8
Apple iPhone OS=4.3.0
Apple iPhone OS=4.3.1
Apple iPhone OS=4.3.2
Apple iPhone OS=4.3.3
Apple iPhone OS=4.3.5
Apple iPhone OS=5.0
Apple iPhone OS=5.0.1
Apple iPhone OS=5.1
Apple iPhone OS=5.1.1
Apple iPhone OS=6.0
Apple iPhone OS=6.0.1
Apple iPhone OS=6.0.2
Apple iPhone OS=6.1
Apple iPhone OS=6.1.2
Apple iPhone OS=6.1.3
Remediation
Patch Available
Event History
Dec 21, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0841?
CVE-2012-0841 has a severity rating that indicates it can lead to denial of service due to high CPU consumption.
2
How do I fix CVE-2012-0841?
To fix CVE-2012-0841, upgrade libxml2 to version 2.8.0 or later, as this version addresses the vulnerability.
3
What systems are affected by CVE-2012-0841?
CVE-2012-0841 affects various versions of libxml2 prior to 2.8.0 and certain iOS versions up to 6.1.4.
4
What type of attack does CVE-2012-0841 enable?
CVE-2012-0841 enables context-dependent attackers to cause denial of service through crafted XML data.
5
Who is the vendor for CVE-2012-0841?
The vendor for CVE-2012-0841 is xmlsoft, the developers of the libxml2 library.