CVE-2010-4008
Summary
| CVE | CVE-2010-4008 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-11-17 01:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Openoffice | All | All | All | All |
| Application | Apache | Openoffice | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Application | Apple | Itunes | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 10.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 10.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 9.10 | All | All | All |
| Operating System | Debian | Debian Linux | 5.0 | All | All | All |
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Application | Chrome | All | All | All | All | |
| Operating System | Opensuse | Opensuse | 11.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 11.2 | All | All | All |
| Operating System | Opensuse | Opensuse | 11.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 6.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 10 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11 | - | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11 | sp1 | All | All |
| Application | Xmlsoft | Libxml2 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of iTunes 10.2 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| About the security content of Safari 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| 58731 - chromium - An open-source project to help move the web forward. - Monorail | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit, Issue Tracking, Patch, Vendor Advisory |
| Google Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Vendor Advisory |
| About the security content of iOS 4.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| '[security bulletin] HPSBGN02970 rev.1 - HP Rapid Deployment Pack (RDP) or HP Insight Control Server ' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| [xml] Release of libxml2-2.7.8 | af854a3a-2127-422b-91ae-364da2661108 | mail.gnome.org | Mailing List, Release Notes, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Google Chrome Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| APPLE-SA-2010-11-22-1 iOS 4.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Debian update for libxml2 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| APPLE-SA-2011-03-02-1 iTunes 10.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Apple iOS Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| OpenOffice.org Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:023 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| APPLE-SA-2011-03-09-2 Safari 5.0.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| libxml2 'XPATH' Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| About the security content of Mac OS X v10.6.7 and Security Update 2011-001 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| CVE-2010-4008 | af854a3a-2127-422b-91ae-364da2661108 | www.openoffice.org | Third Party Advisory |
| Debian -- Security Information -- DSA-2128-1 libxml2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| USN-1016-1: libxml2 vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2010:243 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| Bkis Blog » Libxml2 vulnerability in Google Chrome and Apple Safari | af854a3a-2127-422b-91ae-364da2661108 | blog.bkis.com | Broken Link |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| '[security bulletin] HPSBMA02662 SSRT100409 rev.1 - HP System Management Homepage (SMH) for Linux and' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| libxml XPath Denial of Service Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.