Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libxml2 | — | Apply OS X security update 2005-001 | Dec 16, 2011 | Mar 1, 2005 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Mar 1, 2005 |
| Freebsd | — | Upgrade libxml2Upgrade libxml | Dec 10, 2025 | Nov 9, 2004 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Mar 1, 2005 |
| Suse | — | Upgrade libxml-64bitUpgrade libxml-develUpgrade libxml2-64bitUpgrade libxmlUpgrade libxml-x86Upgrade libxml2-x86Upgrade libxml2-develUpgrade libxml-32bitUpgrade libxml2-32bitUpgrade libxml2 | Feb 17, 2015 | Mar 1, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub