Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Chrome | * | 13.0.782.215 (excluding) | |
| Red Hat Enterprise Linux 6 | RedHat | libxml2-0:2.7.6-4.el6 | * |
| Red Hat Enterprise Linux 6 | RedHat | mingw32-libxml2-0:2.7.6-6.el6_3 | * |
| Chromium-browser | Ubuntu | lucid | * |
| Chromium-browser | Ubuntu | maverick | * |
| Chromium-browser | Ubuntu | natty | * |
| Chromium-browser | Ubuntu | upstream | * |
| Libxml2 | Ubuntu | hardy | * |
| Libxml2 | Ubuntu | lucid | * |
| Libxml2 | Ubuntu | maverick | * |
| Libxml2 | Ubuntu | natty | * |
| Libxml2 | Ubuntu | oneiric | * |
| Libxml2 | Ubuntu | upstream | * |