Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-libs/libxml2.Upgrade app-emulation/emul-linux-x86-baselibs. | Oct 30, 2017 | Apr 25, 2013 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Apr 25, 2013 |
| Suse | — | Upgrade libxml2-docUpgrade libxml2-debuginfo-32bitUpgrade libxml2-x86Upgrade libxml2-debuginfo-x86Upgrade python-libxml2Upgrade libxml2-32bitUpgrade libxml2-devel-32bitUpgrade libxml2Upgrade libxml2-develUpgrade libxml2-2-32bitUpgrade libxml2-toolsUpgrade libxml2-debugsourceUpgrade libxml2-2Upgrade libxml2-debuginfo | Dec 12, 2013 | Apr 25, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Apr 25, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub