Back

HIGH

libxml2: Heap-based buffer overflow by adding new namespace node to an existing nodeset or merging nodesets

Published Sep 2, 2011

Description

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 2, 2011
Updated Aug 6, 2024
Reserved May 9, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 27, 2011