libxml2 Hash Collision Denial Of Service Vulnerability
BID:52107
Info
libxml2 Hash Collision Denial Of Service Vulnerability
| Bugtraq ID: | 52107 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-0841 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2012 12:00AM |
| Updated: | May 07 2015 05:13PM |
| Credit: | Juraj Somorovsky |
| Vulnerable: |
XMLSoft Libxml2 2.7.8 XMLSoft Libxml2 2.7.7 XMLSoft Libxml2 2.7.6 XMLSoft Libxml2 2.7.5 XMLSoft Libxml2 2.7.4 XMLSoft Libxml2 2.7.3 XMLSoft Libxml2 2.7.2 XMLSoft Libxml2 2.7.1 XMLSoft Libxml2 2.7 XMLSoft Libxml2 2.6.32 XMLSoft Libxml2 2.6.31 XMLSoft Libxml2 2.6.30 XMLSoft Libxml2 2.6.26 XMLSoft Libxml2 2.6.22 XMLSoft Libxml2 2.6.20 XMLSoft Libxml2 2.6.18 XMLSoft Libxml2 2.6.17 XMLSoft Libxml2 2.6.16 XMLSoft Libxml2 2.6.15 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.14 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.13 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.12 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.11 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6 .0 XMLSoft Libxml2 2.5.11 XMLSoft Libxml2 2.5.11 XMLSoft Libxml2 2.5.10 XMLSoft Libxml2 2.5.10 XMLSoft Libxml2 2.5.8 XMLSoft Libxml2 2.5.8 XMLSoft Libxml2 2.5.4 XMLSoft Libxml2 2.5.4 XMLSoft Libxml2 2.5.1 XMLSoft Libxml2 2.4.30 XMLSoft Libxml2 2.4.29 XMLSoft Libxml2 2.4.28 XMLSoft Libxml2 2.4.27 XMLSoft Libxml2 2.4.26 XMLSoft Libxml2 2.4.24 XMLSoft Libxml2 2.4.23 XMLSoft Libxml2 2.4.22 XMLSoft Libxml2 2.4.21 XMLSoft Libxml2 2.4.20 XMLSoft Libxml2 2.4.19 XMLSoft Libxml2 2.4.18 XMLSoft Libxml2 2.4.17 XMLSoft Libxml2 2.4.16 XMLSoft Libxml2 2.4.15 XMLSoft Libxml2 2.4.14 XMLSoft Libxml2 2.4.13 XMLSoft Libxml2 2.4.12 XMLSoft Libxml2 2.4.11 XMLSoft Libxml2 2.4.10 XMLSoft Libxml2 2.4.9 XMLSoft Libxml2 2.4.8 XMLSoft Libxml2 2.4.7 XMLSoft Libxml2 2.4.6 XMLSoft Libxml2 2.4.5 XMLSoft Libxml2 2.4.4 XMLSoft Libxml2 2.4.3 XMLSoft Libxml2 2.4.2 XMLSoft Libxml2 2.3.14 XMLSoft Libxml2 2.3.13 XMLSoft Libxml2 2.3.12 XMLSoft Libxml2 2.3.10 XMLSoft Libxml2 2.3.8 XMLSoft Libxml2 2.3.8 XMLSoft Libxml2 2.3.7 XMLSoft Libxml2 2.3.6 XMLSoft Libxml2 2.3.5 XMLSoft Libxml2 2.3.4 XMLSoft Libxml2 2.2.11 XMLSoft Libxml2 2.2.10 XMLSoft Libxml2 2.2.7 XMLSoft Libxml2 2.2.6 XMLSoft Libxml2 2.2.5 XMLSoft Libxml2 2.2.4 XMLSoft Libxml2 2.2.3 XMLSoft Libxml2 2.6.9 XMLSoft Libxml2 2.6.8 XMLSoft Libxml2 2.6.7 XMLSoft Libxml2 2.6.6 XMLSoft Libxml2 2.6.5 XMLSoft Libxml2 2.6.4 XMLSoft Libxml2 2.6.3 XMLSoft Libxml2 2.6.27 XMLSoft Libxml2 2.6.2 XMLSoft Libxml2 2.6.1 XMLSoft Libxml2 2.6.0 XMLSoft Libxml2 2.5.7 XMLSoft Libxml2 2.5.0 XMLSoft Libxml2 2.4.25 XMLSoft Libxml2 2.4.23 XMLSoft Libxml2 2.4.1 XMLSoft Libxml2 2.3.3 XMLSoft Libxml2 2.3.2 XMLSoft Libxml2 2.3.11 XMLSoft Libxml2 2.3.1 XMLSoft Libxml2 2.3.0 XMLSoft Libxml2 2.2.9 XMLSoft Libxml2 2.2.8 XMLSoft Libxml2 2.2.2 XMLSoft Libxml2 2.2.1 XMLSoft Libxml2 2.2.0 XMLSoft Libxml2 2.1.1 XMLSoft Libxml2 2.1.0 XMLSoft Libxml2 2.0.0 Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 VMWare ESXi 5.0 VMWare ESXi 4.1 VMWare ESXi 4.0 VMWare ESXi 3.5 VMWare ESX 4.1 VMWare ESX 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS Sun Solaris 9 Sun Solaris 11 Sun Solaris 10 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux CentOS CentOS 6 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager Utility Services 1.1 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple Apple TV 5.0 |
| Not Vulnerable: | |
Discussion
libxml2 Hash Collision Denial Of Service Vulnerability
libxml2 is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted requests to the affected application that uses a hash table.
Successful exploits may allow attackers to cause a hash collision resulting in excessive CPU resource consumption, effectively denying further service to legitimate users.
libxml2 is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted requests to the affected application that uses a hash table.
Successful exploits may allow attackers to cause a hash collision resulting in excessive CPU resource consumption, effectively denying further service to legitimate users.
Exploit / POC
libxml2 Hash Collision Denial Of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
libxml2 Hash Collision Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva libxml2-devel-2.7.1-1.11mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-python-2.7.1-1.11mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-utils-2.7.1-1.11mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2_2-2.7.1-1.11mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva libxml2-devel-2.7.8-6.5-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-python-2.7.8-6.5-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2-utils-2.7.8-6.5-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libxml2_2-2.7.8-6.5-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
libxml2 Hash Collision Denial Of Service Vulnerability
References:
References: