Tracker / CVE-2010-4008
CVE-2010-4008
Medium 4.3
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Affected products and versions
| apache | openoffice · 2.0.0 → 2.4.3 |
|---|---|
| apache | openoffice · 3.0.0 → 3.3.0 |
| apple | iphone_os · … → 4.2 |
| apple | itunes · … → 10.2 |
| apple | mac_os_x · … → 10.6.7 |
| apple | safari · … → 5.0.4 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| chrome · … → 7.0.517.44 | |
| opensuse | opensuse |
| redhat | enterprise_linux_desktop |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_eus |
| redhat | enterprise_linux_workstation |
| suse | suse_linux_enterprise_server |
| xmlsoft | libxml2 · … → 2.7.8 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.