Back

MEDIUM

libxslt: Heap-buffer overflow caused by bad cast in XSL transforms

Published Aug 31, 2012

Description

libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Aug 31, 2012
Updated Aug 6, 2024
Reserved May 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 31, 2012