Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libxml | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Sep 12, 2008 |
| Apple Safari | — | Upgrade to Apple Safari version 4.0Uninstall Apple Safari on Windows | Jan 5, 2012 | Sep 12, 2008 |
| Centos_linux | — | Upgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Dec 1, 2016 | Sep 12, 2008 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Sep 12, 2008 |
| Freebsd | — | Upgrade libxml2 | Dec 10, 2025 | Oct 15, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Sep 12, 2008 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Oct 16, 2024 | Sep 12, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade libxml2Upgrade libxml2-docUpgrade libxml2-32bitUpgrade libxml2-devel-32bitUpgrade libxml2-x86Upgrade libxml2-64bitUpgrade libxml2-develUpgrade libxml2-devel-64bit | Feb 17, 2015 | Sep 12, 2008 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Sep 12, 2008 |
| Vmsa 2008 0017 | — | Apply ESX350-200811405-SG. | Nov 19, 2010 | Sep 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub