libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxml2 | Aug 30, 2017 | Dec 21, 2012 |
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Dec 21, 2012 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Aug 28, 2015 | Dec 21, 2012 |
| Centos_linux | — | Upgrade libxml2Upgrade libxml2-staticUpgrade libxml2-pythonUpgrade mingw32-libxml2Upgrade mingw32-libxml2-staticUpgrade libxml2-devel | Dec 1, 2016 | Dec 21, 2012 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Dec 21, 2012 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Dec 21, 2012 |
| Oracle Solaris | — | Upgrade libxml2 to version 2.7.6-0.175.0.10.0.4.0 on Solaris 11.0 | May 29, 2017 | Dec 21, 2012 |
| Oracle_linux | — | Upgrade libxml2-develUpgrade mingw32-libxml2-staticUpgrade libxml2Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade mingw32-libxml2 | Oct 16, 2024 | Dec 21, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 21, 2012 |
| Suse | — | Upgrade libxml2-debuginfoUpgrade libxml2-x86Upgrade libxml2-debuginfo-32bitUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-debugsourceUpgrade libxml2-docUpgrade libxml2-32bitUpgrade libxml2-devel-64bitUpgrade libxml2-devel-32bitUpgrade libxml2-pythonUpgrade libxml2-64bit | Feb 17, 2015 | Dec 21, 2012 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Dec 21, 2012 |
| Vmsa 2012 0012 | — | Upgrade VMware ESXi 4.0 to build number 787047Upgrade VMware ESXi 5.0 to build number 764879Upgrade VMware ESXi 4.1 to build number 800380 | Jul 18, 2012 | Jul 18, 2012 |
| Vmsa 2012 0013 | — | Upgrade VMware ESX 4.1 to build number 800380Upgrade VMware ESX 4.0 to build number 787047 | Sep 17, 2012 | Sep 17, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub