[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2012-036 --- libxml2

ID: oval:org.secpod.oval:def:1601297Date: (C)2020-11-27   (M)2023-11-09
Class: PATCHFamily: unix




A heap-based buffer overflow flaw was found in the way libxml2 decoded entity references with long names. A remote attacker could provide a specially-crafted XML file that, when opened in an application linked against libxml2, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application. An out-of-bounds memory read flaw was found in libxml2. A remote attacker could provide a specially-crafted XML file that, when opened in an application linked against libxml2, would cause the application to crash

Platform:
Amazon Linux AMI
Product:
libxml2
Reference:
ALAS-2012-36
CVE-2011-3905
CVE-2011-3919
CVE    2
CVE-2011-3905
CVE-2011-3919
CPE    2
cpe:/o:amazon:linux
cpe:/a:libxml2:libxml2

© SecPod Technologies