imPC@ndo IT

Tracker / CVE-2010-4008

CVE-2010-4008

Medium 4.3

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.

Affected products and versions

apache openoffice · 2.0.0 → 2.4.3
apache openoffice · 3.0.0 → 3.3.0
apple iphone_os · … → 4.2
apple itunes · … → 10.2
apple mac_os_x · … → 10.6.7
apple safari · … → 5.0.4
canonical ubuntu_linux
debian debian_linux
google chrome · … → 7.0.517.44
opensuse opensuse
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_server_eus
redhat enterprise_linux_workstation
suse suse_linux_enterprise_server
xmlsoft libxml2 · … → 2.7.8

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References