CVE-2012-2870: Medium severity Apple iPhone OS vulnerability
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2870?
The severity of CVE-2012-2870 is classified as moderate due to the potential for denial of service exploits.
How do I fix CVE-2012-2870?
To fix CVE-2012-2870, update Google Chrome to version 21.0.1180.89 or later, or upgrade libxslt to version 1.1.27 or newer.
Which versions of Google Chrome are affected by CVE-2012-2870?
Google Chrome versions prior to 21.0.1180.89 are affected by CVE-2012-2870.
What software does CVE-2012-2870 affect?
CVE-2012-2870 affects Google Chrome and versions of libxslt up to 1.1.26.
How can an attacker exploit CVE-2012-2870?
An attacker can exploit CVE-2012-2870 by using a crafted XSLT expression that causes a denial of service through improper memory management.