CVE-2012-2871: Medium severity Apple iPhone OS vulnerability
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the xmlNs data structure in include/libxml/tree.h.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2871?
CVE-2012-2871 has a medium severity rating, as it may lead to denial of service or other unknown impacts.
How do I fix CVE-2012-2871?
To fix CVE-2012-2871, update Google Chrome to version 21.0.1180.89 or later, and ensure that your version of libxml2 is 2.9.0 or newer.
Which software versions are affected by CVE-2012-2871?
CVE-2012-2871 affects Apple iPhone OS versions up to 6.1.4 and Google Chrome versions up to 21.0.1180.88.
What types of attacks may exploit CVE-2012-2871?
CVE-2012-2871 may be exploited through crafted documents that manipulate XSL transforms, leading to denial of service.
Is CVE-2012-2871 still a concern today?
CVE-2012-2871 is less of a concern today as it primarily affects outdated software versions that should no longer be in use.