libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities
BID:48056
Info
libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 48056 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1944 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2011 12:00AM |
| Updated: | Apr 13 2015 08:35PM |
| Credit: | Chris Evans |
| Vulnerable: |
XMLSoft Libxml2 2.7.8 XMLSoft Libxml2 2.7.7 XMLSoft Libxml2 2.7.6 XMLSoft Libxml2 2.7.5 XMLSoft Libxml2 2.7.4 XMLSoft Libxml2 2.7.3 XMLSoft Libxml2 2.7.2 XMLSoft Libxml2 2.7.1 XMLSoft Libxml2 2.7 XMLSoft Libxml2 2.6.32 XMLSoft Libxml2 2.6.31 XMLSoft Libxml2 2.6.30 XMLSoft Libxml2 2.6.26 XMLSoft Libxml2 2.6.22 XMLSoft Libxml2 2.6.20 XMLSoft Libxml2 2.6.18 XMLSoft Libxml2 2.6.17 XMLSoft Libxml2 2.6.16 XMLSoft Libxml2 2.6.15 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6 .0 XMLSoft Libxml2 2.5.11 XMLSoft Libxml2 2.5.11 XMLSoft Libxml2 2.5.10 XMLSoft Libxml2 2.5.10 XMLSoft Libxml2 2.5.8 XMLSoft Libxml2 2.5.8 XMLSoft Libxml2 2.5.4 XMLSoft Libxml2 2.5.4 XMLSoft Libxml2 2.5.1 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.27 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6.0 XMLSoft Libxml2 2.5.7 XMLSoft Libxml2 2.5.0 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 VMWare ESXi 5.0 VMWare ESXi 4.1 VMWare ESXi 4.0 VMWare ESXi 3.5 VMWare ESX 5.0 VMWare ESX 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Sun Solaris 9 Sun Solaris 10 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 HP System Management Homepage 7.0 HP System Management Homepage 6.3 HP System Management Homepage 6.2 HP System Management Homepage 6.1 HP System Management Homepage 6.0 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 CentOS CentOS 6 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Proactive Contact 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E 7.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.7.3 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple Mac OS X 10.6 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 Apple Apple TV 5.0 Apple Apple TV 4.4 |
| Not Vulnerable: |
Apple Mac Os X Server 10.7.4 Apple Mac Os X 10.7.4 |
Exploit / POC
libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities
The following proof-of-concept XPath expression is available:
//@*/preceding::node()/ancestor::node()/ancestor::foo['foo']
The following proof-of-concept XPath expression is available:
//@*/preceding::node()/ancestor::node()/ancestor::foo['foo']
Solution / Fix
libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.7.2
Apple Mac OS X 10.6.8
Apple Mac OS X Server 10.7.2
Mandriva Linux Mandrake 2009.0 x86_64
Apple Mac OS X 10.7.3
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.7.2
-
Apple MacOSXUpdCombo10.7.4.dmg
For OS X Lion v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.8
-
Apple SecUpd2012-002Snow.dmg
For Mac OS X v10.6.8
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.7.2
-
Apple MacOSXServerUpdCombo10.7.4.dmg
For OS X Lion Server v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva lib64xml1-1.8.17-14.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64xml1-devel-1.8.17-14.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64xml2-devel-2.7.1-1.7mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64xml2_2-2.7.1-1.7mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-python-2.7.1-1.7mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-utils-2.7.1-1.7mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X 10.7.3
-
Apple MacOSXUpd10.7.4.dmg
For OS X Lion v10.7.3
http://www.apple.com/support/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva libxml1-1.8.17-14.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml1-devel-1.8.17-14.2mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-devel-2.7.1-1.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-python-2.7.1-1.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-utils-2.7.1-1.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2_2-2.7.1-1.7mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
libxml2 Invalid XPath Multiple Memory Corruption Vulnerabilities
References:
References:
- About the security content of Apple TV 5.1 (Apple)
- CVE-2011-1944 Denial of Service (DoS) vulnerability in libxml2 (Oracle)
- Fix some potential problems on reallocation failures (Chris Evans)
- libxml vulnerability and interesting integer issues (Chris Evans)
- libxml2 Homepage (xmlsoft)
- 2014-11 Security Bulletin: CTPView: Multiple Security vulnerabilities resolved b (Juniper)
- ASA-2011-411 (Avaya)
- ASA-2012-124 libxml2 security update (RHSA-2012-0017) (avaya)
- HPSBMU02786 SSRT100877 rev.1 - HP System Management Homepage (SMH) Running on Li (HP)
- Oracle Critical Patch Update Advisory - January 2015 Oracle Advisory (Oracle)
- Xerox Security Bulletin XRX12-009 (Xerox)