An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Oct 19, 2018 | Oct 18, 2018 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest versionApply OS X security update 2017-004 El Capitan | Oct 19, 2018 | Feb 7, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 7, 2018 |
| Centos_linux | — | Upgrade chromium-browser-debuginfoUpgrade chromium-browser | Aug 28, 2019 | Feb 7, 2018 |
| Debian | — | Upgrade libxml2 | Feb 25, 2019 | Feb 7, 2018 |
| Freebsd | — | Upgrade chromium | Oct 23, 2017 | Oct 21, 2017 |
| Gentoo Linux | — | Upgrade www-client/google-chrome.Upgrade www-client/chromium. | Oct 30, 2017 | Oct 23, 2017 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Feb 28, 2018 | Oct 18, 2017 |
| Redhat_linux | — | Upgrade chromium-browser-debuginfoUpgrade chromium-browser | Oct 25, 2017 | Oct 17, 2017 |
| Suse | — | Upgrade libxml2-2-32bitUpgrade libxml2-devel-32bitUpgrade libxml2-32bitUpgrade libxml2Upgrade libxml2-docUpgrade libxml2-x86Upgrade python-libxml2Upgrade libxml2-toolsUpgrade libxml2-develUpgrade libxml2-pythonUpgrade chromedriverUpgrade chromiumUpgrade libxml2-2 | Oct 30, 2017 | Oct 17, 2017 |
| Ubuntu | — | Upgrade chromium-browserUpgrade libxml2 | Nov 19, 2024 | Feb 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub