An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Oct 19, 2018 | Feb 7, 2018 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest versionApply OS X security update 2017-004 El Capitan | Oct 19, 2018 | Feb 7, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 7, 2018 |
| Centos_linux | — | Upgrade chromium-browser-debuginfoUpgrade chromium-browser | Aug 28, 2019 | Feb 7, 2018 |
| Debian | — | Upgrade libxml2 | Feb 25, 2019 | Feb 7, 2018 |
| Freebsd | — | Upgrade chromium | Oct 23, 2017 | Oct 21, 2017 |
| Gentoo Linux | — | Upgrade www-client/google-chrome.Upgrade www-client/chromium. | Oct 30, 2017 | Oct 23, 2017 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Feb 28, 2018 | Oct 18, 2017 |
| Redhat_linux | — | Upgrade chromium-browserUpgrade chromium-browser-debuginfo | Oct 25, 2017 | Oct 17, 2017 |
| Suse | — | Upgrade libxml2-x86Upgrade python-libxml2Upgrade libxml2-devel-32bitUpgrade libxml2-docUpgrade libxml2Upgrade libxml2-32bitUpgrade libxml2-2-32bitUpgrade libxml2-2Upgrade libxml2-toolsUpgrade libxml2-develUpgrade libxml2-pythonUpgrade chromedriverUpgrade chromium | Oct 30, 2017 | Oct 17, 2017 |
| Ubuntu | — | Upgrade libxml2Upgrade chromium-browser | Nov 19, 2024 | Feb 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub