libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
BID:27248
Info
libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
| Bugtraq ID: | 27248 |
| Class: | Design Error |
| CVE: |
CVE-2007-6284 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2008 12:00AM |
| Updated: | Apr 13 2015 09:28PM |
| Credit: | Brad Fitzpatrick is credited with the discovery of this vulnerability. |
| Vulnerable: |
VMWare ESX Server 2.5.5 patch 4 VMWare ESX Server 2.5.5 patch 2 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Patch 16 VMWare ESX Server 2.5.4 patch 15 VMWare ESX Server 2.5.4 patch 13 VMWare ESX Server 2.5.4 Patch 10 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VideoLAN VLC media player 0.8.6 g VideoLAN VLC media player 0.8.6 d VideoLAN VLC media player 0.8.6 VideoLAN VLC media player 0.8.6f VideoLAN VLC media player 0.8.6e VideoLAN VLC media player 0.8.6c VideoLAN VLC media player 0.8.6b VideoLAN VLC media player 0.8.6a Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 Redhat Fedora 7 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - Peri Application Rel 3.0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self-Service 0 Nortel Networks Enterprise Network Management System Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 Avaya Intuity LX 2.0 Avaya Intuity LX Avaya Intuity AUDIX Avaya EMMC 1.021 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 5.0 Avaya Communication Manager 3.0 Avaya Communication Manager 2.2 Avaya Communication Manager 2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
VMWare ESX Server 2.5.5 patch 6 VMWare ESX Server 2.5.4 Patch 17 VideoLAN VLC media player 0.8.6 h Apple iPod Touch 2.0 Apple iPhone 2.0 |
Discussion
libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
The libxml2 library is prone to a denial-of-service vulnerability because of an infinite-loop flaw.
Exploiting this issue allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable library.
Versions prior to libxml2 2.6.31 are affected by this issue.
The libxml2 library is prone to a denial-of-service vulnerability because of an infinite-loop flaw.
Exploiting this issue allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable library.
Versions prior to libxml2 2.6.31 are affected by this issue.
Exploit / POC
libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
Solution:
The vendor released an upgraded version of libxml2 along with patches. Please see the references for more information.
VideoLAN VLC media player 0.8.6f
VideoLAN VLC media player 0.8.6b
VideoLAN VLC media player 0.8.6e
VideoLAN VLC media player 0.8.6 g
VideoLAN VLC media player 0.8.6 d
VideoLAN VLC media player 0.8.6
Solution:
The vendor released an upgraded version of libxml2 along with patches. Please see the references for more information.
VideoLAN VLC media player 0.8.6f
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
VideoLAN VLC media player 0.8.6b
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
VideoLAN VLC media player 0.8.6e
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
VideoLAN VLC media player 0.8.6 g
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
VideoLAN VLC media player 0.8.6 d
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
VideoLAN VLC media player 0.8.6
-
VideoLAN VLC media player 0.8.6h
http://www.videolan.org/vlc/
References
libxml2 'xmlCurrentChar()' UTF-8 Parsing Remote Denial of Service Vulnerability
References:
References:
- Bugzilla Bug 425927: CVE-2007-6284 libxml2: infinite loop in UTF-8 decoding (Red Hat)
- [xml] Security flaw affecting all previous libxml2 releases (Daniel Veillard)
- Sun Alert ID: 103201 - Security Vulnerability in the libxml2 Library may Lead to (Sun Microsystems)
- VideoLAN Changelog/0.8.6h (VideoLAN)
- VLC Homepage (VideoLAN)
- XMLSoft Changelog (XMLSoft)
- XMLSoft Homepage (XMLSoft)
- XMLSoft News (XMLSoft)
- 2008008708: Nortel response to Sun Alert 201514 - Security Vulnerability in the (Nortel Networks)
- ASA-2008-050 - libxml2 security update (RHSA-2008-0032) (Avaya)
- RHSA-2008:0032-3: libxml2 security update (Red Hat)