Buffer overflow in Libxml2 - CVE-2012-5134

 

Buffer overflow in Libxml2 - CVE-2012-5134

Published: November 28, 2012 / Updated: July 28, 2020


Vulnerability identifier: #VU32739
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5134
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.


Affected software

Libxml2
Amazon Linux AMI
SUSE Linux
Slackware Linux
libxml2 (Alpine package)

How to mitigate CVE-2012-5134

Install update from vendor's website.

libxml2 (Alpine package) - update to 2.7.8-r5

External References

Related Security Bulletins