Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libxml | — | Upgrade macOS to the latest versionApply OS X security update 2012-002 | Jul 16, 2012 | Sep 2, 2011 |
| Apple Osx Loginwindow | — | Apply OS X security update 2012-002Upgrade macOS to the latest version | Aug 28, 2015 | Sep 2, 2011 |
| Centos_linux | — | Upgrade mingw32-libxml2-staticUpgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-develUpgrade mingw32-libxml2 | Dec 1, 2016 | Sep 2, 2011 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Sep 2, 2011 |
| Freebsd | — | Upgrade linux-f10-libxml2Upgrade libxml2Upgrade libxml | Dec 10, 2025 | Nov 10, 2011 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Sep 2, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Sep 2, 2011 |
| Oracle_linux | — | Upgrade mingw32-libxml2-staticUpgrade libxml2Upgrade libxml2-develUpgrade mingw32-libxml2Upgrade libxml2-pythonUpgrade libxml2-static | Oct 16, 2024 | Sep 2, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 27, 2011 |
| Suse | — | Upgrade libxml2-x86Upgrade libxml2-devel-32bitUpgrade python313-libxml2Upgrade libxml2-2-32bitUpgrade libxml2-docUpgrade libxml2-32bitUpgrade libxml2-toolsUpgrade libxml2Upgrade libxml2-2Upgrade libxml2-devel | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Sep 2, 2011 |
| Vmsa 2012 0008 | — | Upgrade VMware ESX 4.1 to build number 659051 | Aug 17, 2012 | Sep 2, 2011 |
| Vmsa 2012 0012 | — | Upgrade VMware ESXi 4.0 to build number 787047Upgrade VMware ESXi 5.0 to build number 764879Upgrade VMware ESXi 4.1 to build number 800380 | Jul 18, 2012 | Sep 2, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub