libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
BID:51084
Info
libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
| Bugtraq ID: | 51084 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3905 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2011 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Google Chrome Security Team (Inferno) |
| Vulnerable: |
XMLSoft Libxml2 2.7.8 XMLSoft Libxml2 2.7.7 XMLSoft Libxml2 2.7.6 XMLSoft Libxml2 2.7.5 XMLSoft Libxml2 2.7.4 XMLSoft Libxml2 2.7.3 XMLSoft Libxml2 2.7.2 XMLSoft Libxml2 2.7.1 XMLSoft Libxml2 2.7 XMLSoft Libxml2 2.6.32 XMLSoft Libxml2 2.6.31 XMLSoft Libxml2 2.6.30 XMLSoft Libxml2 2.6.26 XMLSoft Libxml2 2.6.22 XMLSoft Libxml2 2.6.20 XMLSoft Libxml2 2.6.18 XMLSoft Libxml2 2.6.17 XMLSoft Libxml2 2.6.16 XMLSoft Libxml2 2.6.15 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6 .0 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.27 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6.0 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 VMWare ESXi 5.0 VMWare ESXi 4.1 VMWare ESXi 4.0 VMWare ESXi 3.5 VMWare ESX 5.0 VMWare ESX 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Sun Solaris 9 Sun Solaris 11 Sun Solaris 10 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Google Chrome 15.0.874 102 Google Chrome 9.0.597.94 Google Chrome 9.0.597.84 Google Chrome 9.0.597.107 Google Chrome 8.0.552.344 Google Chrome 8.0.552.310 Google Chrome 8.0.552.309 Google Chrome 8.0.552.308 Google Chrome 8.0.552.307 Google Chrome 8.0.552.306 Google Chrome 8.0.552.305 Google Chrome 8.0.552.304 Google Chrome 8.0.552.303 Google Chrome 8.0.552.302 Google Chrome 8.0.552.301 Google Chrome 8.0.552.300 Google Chrome 8.0.552.237 Google Chrome 8.0.552.226 Google Chrome 8.0.552.225 Google Chrome 8.0.552.224 Google Chrome 8.0.552.223 Google Chrome 8.0.552.222 Google Chrome 8.0.552.221 Google Chrome 8.0.552.220 Google Chrome 8.0.552.219 Google Chrome 8.0.552.218 Google Chrome 8.0.552.217 Google Chrome 8.0.552.216 Google Chrome 8.0.552.215 Google Chrome 8.0.552.214 Google Chrome 8.0.552.213 Google Chrome 8.0.552.212 Google Chrome 8.0.552.211 Google Chrome 8.0.552.210 Google Chrome 8.0.552.21 Google Chrome 8.0.552.209 Google Chrome 8.0.552.208 Google Chrome 8.0.552.207 Google Chrome 8.0.552.206 Google Chrome 8.0.552.205 Google Chrome 8.0.552.204 Google Chrome 8.0.552.203 Google Chrome 8.0.552.202 Google Chrome 8.0.552.201 Google Chrome 8.0.552.200 Google Chrome 8.0.552.20 Google Chrome 8.0.552.2 Google Chrome 8.0.552.19 Google Chrome 8.0.552.18 Google Chrome 8.0.552.17 Google Chrome 8.0.552.16 Google Chrome 8.0.552.15 Google Chrome 8.0.552.14 Google Chrome 8.0.552.13 Google Chrome 8.0.552.12 Google Chrome 8.0.552.11 Google Chrome 8.0.552.105 Google Chrome 8.0.552.104 Google Chrome 8.0.552.103 Google Chrome 8.0.552.102 Google Chrome 8.0.552.101 Google Chrome 8.0.552.100 Google Chrome 8.0.552.10 Google Chrome 8.0.552.1 Google Chrome 8.0.552.0 Google Chrome 8.0.551.1 Google Chrome 8.0.551.0 Google Chrome 8.0.550.0 Google Chrome 8.0.549.0 Google Chrome 7.0.548.0 Google Chrome 7.0.547.1 Google Chrome 7.0.547.0 Google Chrome 7.0.544.0 Google Chrome 7.0.542.0 Google Chrome 7.0.541.0 Google Chrome 7.0.540.0 Google Chrome 7.0.539.0 Google Chrome 7.0.538.0 Google Chrome 7.0.537.0 Google Chrome 7.0.536.4 Google Chrome 7.0.536.3 Google Chrome 7.0.536.2 Google Chrome 7.0.536.1 Google Chrome 7.0.536.0 Google Chrome 7.0.535.2 Google Chrome 7.0.535.1 Google Chrome 7.0.531.2 Google Chrome 7.0.531.1 Google Chrome 7.0.531.0 Google Chrome 7.0.530.0 Google Chrome 7.0.529.2 Google Chrome 7.0.529.1 Google Chrome 7.0.529.0 Google Chrome 7.0.528.0 Google Chrome 7.0.526.0 Google Chrome 7.0.525.0 Google Chrome 7.0.524.0 Google Chrome 7.0.522.0 Google Chrome 7.0.521.0 Google Chrome 7.0.520.0 Google Chrome 7.0.519.0 Google Chrome 7.0.518.0 Google Chrome 7.0.517.9 Google Chrome 7.0.517.8 Google Chrome 7.0.517.7 Google Chrome 7.0.517.6 Google Chrome 7.0.517.5 Google Chrome 7.0.517.44 Google Chrome 7.0.517.43 Google Chrome 7.0.517.42 Google Chrome 7.0.517.41 Google Chrome 7.0.517.40 Google Chrome 7.0.517.4 Google Chrome 7.0.517.39 Google Chrome 7.0.517.38 Google Chrome 7.0.517.37 Google Chrome 7.0.517.36 Google Chrome 7.0.517.35 Google Chrome 7.0.517.34 Google Chrome 7.0.517.33 Google Chrome 7.0.517.32 Google Chrome 7.0.517.31 Google Chrome 7.0.517.30 Google Chrome 7.0.517.29 Google Chrome 7.0.517.28 Google Chrome 7.0.517.27 Google Chrome 7.0.517.26 Google Chrome 7.0.517.25 Google Chrome 7.0.517.24 Google Chrome 7.0.517.23 Google Chrome 7.0.517.22 Google Chrome 7.0.517.21 Google Chrome 7.0.517.20 Google Chrome 7.0.517.2 Google Chrome 7.0.517.19 Google Chrome 7.0.517.18 Google Chrome 7.0.517.17 Google Chrome 7.0.517.16 Google Chrome 7.0.517.14 Google Chrome 7.0.517.13 Google Chrome 7.0.517.12 Google Chrome 7.0.517.11 Google Chrome 7.0.517.10 Google Chrome 7.0.517.0 Google Chrome 7.0.516.0 Google Chrome 7.0.515.0 Google Chrome 7.0.514.1 Google Chrome 7.0.514.0 Google Chrome 7.0.513.0 Google Chrome 7.0.512.0 Google Chrome 7.0.511.4 Google Chrome 7.0.511.2 Google Chrome 7.0.511.1 Google Chrome 7.0.510.0 Google Chrome 7.0.509.0 Google Chrome 7.0.507.3 Google Chrome 7.0.507.2 Google Chrome 7.0.507.1 Google Chrome 7.0.507.0 Google Chrome 7.0.506.0 Google Chrome 7.0.505.0 Google Chrome 7.0.504.0 Google Chrome 7.0.503.1 Google Chrome 7.0.503.0 Google Chrome 7.0.500.1 Google Chrome 7.0.500.0 Google Chrome 7.0.499.1 Google Chrome 7.0.499.0 Google Chrome 7.0.498.0 Google Chrome 7.0.497.0 Google Chrome 16 Google Chrome 15.0.874.121 Google Chrome 15.0.874.120 Google Chrome 14.0.835.202 Google Chrome 14.0.835.186 Google Chrome 14.0.835.163 Google Chrome 14 Google Chrome 13.0.782.215 Google Chrome 13.0.782.112 Google Chrome 13.0.782.107 Google Chrome 13 Google Chrome 12.0.742.91 Google Chrome 12.0.742.112 Google Chrome 12.0.742.100 Google Chrome 12 Google Chrome 11.0.696.77 Google Chrome 11.0.696.71 Google Chrome 11.0.696.68 Google Chrome 11.0.696.65 Google Chrome 11.0.696.57 Google Chrome 11.0.696.43 Google Chrome 11.0.672.2 Google Chrome 11 Google Chrome 10.0.648.205 Google Chrome 10.0.648.205 Google Chrome 10.0.648.204 Google Chrome 10.0.648.133 Google Chrome 10.0.648.128 Google Chrome 10.0.648.127 Google Chrome 10.0.648.127 Google Chrome 10 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 SP2 Avaya Messaging Storage Server 5.1 SP1 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E 7.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
Google Chrome 16.0.912.63 |
Discussion
libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
The 'libxml2' library is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application using the library to crash, denying service to legitimate users.
This issue affects libxml2-2.7.7; other versions may also be affected.
NOTE: This issue was previously discussed in BID 51041 (Google Chrome Prior to 16.0.912.63 Multiple Security Vulnerabilities) but has been given its own record to better document it.
The 'libxml2' library is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause the affected application using the library to crash, denying service to legitimate users.
This issue affects libxml2-2.7.7; other versions may also be affected.
NOTE: This issue was previously discussed in BID 51041 (Google Chrome Prior to 16.0.912.63 Multiple Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva libxml2-devel-2.7.1-1.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-python-2.7.1-1.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-utils-2.7.1-1.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2_2-2.7.1-1.9mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
libxml2 Unspecified Out-of-Bounds Remote Denial of Service Vulnerability
References:
References:
- libxml2 Homepage (xmlsoft)
- Multiple Denial of Service (DoS) vulnerabilities in libxml2 (Oracle)
- 2014-11 Security Bulletin: CTPView: Multiple Security vulnerabilities resolved b (Juniper)
- ASA-2012-027 libxml2 security update (RHSA-2012-0018) (Avaya)
- ASA-2012-043: libxml2 security update (RHSA-2012-0016) (Avaya)
- ASA-2012-124 libxml2 security update (RHSA-2012-0017) (avaya)
- Xerox Security Bulletin XRX12-009 (Xerox)