Back

MEDIUM

libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis

Published Nov 16, 2010

Description

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of libxml and libxml2 as shipped with Red Hat Enterprise Linux 3, and it did not affect the version of libxml2 as shipped with Red Hat Enterprise Linux 4.

Metrics

References (36)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Nov 16, 2010
Updated Aug 7, 2024
Reserved Oct 20, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 4, 2010