Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libxml2 | Xmlsoft | 2.6.0 (including) | 2.6.0 (including) |
Libxml2 | Xmlsoft | 2.6.1 (including) | 2.6.1 (including) |
Libxml2 | Xmlsoft | 2.6.2 (including) | 2.6.2 (including) |
Libxml2 | Xmlsoft | 2.6.3 (including) | 2.6.3 (including) |
Libxml2 | Xmlsoft | 2.6.4 (including) | 2.6.4 (including) |
Libxml2 | Xmlsoft | 2.6.5 (including) | 2.6.5 (including) |
Libxml2 | Xmlsoft | 2.6.6 (including) | 2.6.6 (including) |
Libxml2 | Xmlsoft | 2.6.7 (including) | 2.6.7 (including) |
Libxml2 | Xmlsoft | 2.6.8 (including) | 2.6.8 (including) |
Libxml2 | Xmlsoft | 2.6.9 (including) | 2.6.9 (including) |
Libxml2 | Xmlsoft | 2.6.11 (including) | 2.6.11 (including) |
Libxml2 | Xmlsoft | 2.6.12 (including) | 2.6.12 (including) |
Libxml2 | Xmlsoft | 2.6.13 (including) | 2.6.13 (including) |
Libxml2 | Xmlsoft | 2.6.14 (including) | 2.6.14 (including) |
Libxml2 | Xmlsoft | 2.6.16 (including) | 2.6.16 (including) |
Libxml2 | Xmlsoft | 2.6.17 (including) | 2.6.17 (including) |
Libxml2 | Xmlsoft | 2.6.18 (including) | 2.6.18 (including) |
Libxml2 | Xmlsoft | 2.6.20 (including) | 2.6.20 (including) |
Libxml2 | Xmlsoft | 2.6.22 (including) | 2.6.22 (including) |
Libxml2 | Xmlsoft | 2.6.26 (including) | 2.6.26 (including) |
Libxml2 | Xmlsoft | 2.6.27 (including) | 2.6.27 (including) |
Libxml2 | Xmlsoft | 2.6.30 (including) | 2.6.30 (including) |
Libxml2 | Xmlsoft | 2.6.32 (including) | 2.6.32 (including) |
Red Hat Enterprise Linux 5 | RedHat | libxml2-0:2.6.26-2.1.12.el5_7.2 | * |
Red Hat Enterprise Linux 6 | RedHat | libxml2-0:2.7.6-4.el6 | * |
Red Hat Enterprise Linux 6 | RedHat | mingw32-libxml2-0:2.7.6-6.el6_3 | * |
Libxml2 | Ubuntu | devel | * |
Libxml2 | Ubuntu | hardy | * |
Libxml2 | Ubuntu | lucid | * |
Libxml2 | Ubuntu | maverick | * |
Libxml2 | Ubuntu | natty | * |
Libxml2 | Ubuntu | upstream | * |