[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2417-1 libxml2 -- computational denial of service

ID: oval:org.secpod.oval:def:600738Date: (C)2012-02-27   (M)2023-02-20
Class: PATCHFamily: unix




It was discovered that the internal hashing routine of libxml2, a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the hashing algorithm, it is possible to craft input that creates a large amount of collisions. As a result it is possible to perform denial of service attacks against applications using libxml2 functionality because of the computational overhead.

Platform:
Debian 6.0
Product:
libxml2
Reference:
DSA-2417-1
CVE-2012-0841
CVE    1
CVE-2012-0841
CPE    126
cpe:/a:xmlsoft:libxml2
cpe:/a:xmlsoft:libxml2:2.3.9
cpe:/a:xmlsoft:libxml2:2.7.5
cpe:/a:xmlsoft:libxml2:2.3.8
...

© SecPod Technologies