parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libxml2-staticUpgrade libxml2-pythonUpgrade libxml2Upgrade libxml2-devel | Dec 1, 2016 | Jul 10, 2013 |
| Debian | — | Upgrade chromium-browserUpgrade libxml2 | Jul 30, 2024 | Jul 10, 2013 |
| Freebsd | — | Upgrade linux-c6-libxml2Upgrade linux-f10-libxml2Upgrade libxml2 | Dec 10, 2025 | Jul 10, 2013 |
| Gentoo Linux | — | Upgrade dev-lang/v8.Upgrade www-client/chromium.Upgrade dev-libs/libxml2.Upgrade app-emulation/emul-linux-x86-baselibs. | Oct 30, 2017 | Jul 10, 2013 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 12, 2013 | Jul 9, 2013 |
| Oracle_linux | — | Upgrade libxml2Upgrade libxml2-develUpgrade libxml2-staticUpgrade libxml2-python | Oct 16, 2024 | Jul 10, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 9, 2013 |
| Suse | — | Upgrade libxml2-devel-32bitUpgrade libxml2-toolsUpgrade libxml2-32bitUpgrade libxml2-2-32bitUpgrade libxml2-docUpgrade libxml2-pythonUpgrade sle-sdk-releaseUpgrade libxml2Upgrade python-libxml2Upgrade libxml2-2Upgrade libxml2-x86Upgrade libxml2-devel | Feb 17, 2015 | Jul 10, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Jul 10, 2013 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.1 to build number 2323236Upgrade VMware ESXi 5.0 to build number 2210222Upgrade VMware ESXi 5.5 to build number 2068190 | Oct 28, 2015 | Jul 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub