CVE-2007-6284
published 2008-01-12CVE-2007-6284: The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.57%
83.4th percentile
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.6.30.dfsg-3.1 (bookworm) | libxml2 2.6.30.dfsg-3.1 (bookworm) |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| redhat | fedora | — | — |
| redhat | fedora | — | — |
| xmlsoft | libxml2 | >= 0 < 2.6.30.dfsg-3.1 | 2.6.30.dfsg-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.6.30.dfsg-3.1 | 2.6.30.dfsg-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.6.30.dfsg-3.1 | 2.6.30.dfsg-3.1 |
| xmlsoft | libxml2 | >= 0 < 2.6.30.dfsg-3.1 | 2.6.30.dfsg-3.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2008-01-14
CVE-2007-6284 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 vulnerability
Brad Fitzpatrick discovered that libxml2 did not correctly handle certain
UTF-8 sequences. If a remote attacker were able to trick a user or
automated system into processing a specially crafted XML document, the
application linked against libxml2 could enter an infinite loop, leading
to a denial of service via CPU resource consumption.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
libxml2: infinite loop in UTF-8 decoding
vendor_redhat·2008-01-11·CVSS 5.0
CVE-2007-6284 [MEDIUM] CWE-835 libxml2: infinite loop in UTF-8 decoding
libxml2: infinite loop in UTF-8 decoding
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
Debian
CVE-2007-6284: libxml2 - The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent at...
vendor_debian·2007·CVSS 5.0
CVE-2007-6284 [MEDIUM] CVE-2007-6284: libxml2 - The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent at...
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
Scope: local
bookworm: resolved (fixed in 2.6.30.dfsg-3.1)
bullseye: resolved (fixed in 2.6.30.dfsg-3.1)
forky: resolved (fixed in 2.6.30.dfsg-3.1)
sid: resolved (fixed in 2.6.30.dfsg-3.1)
trixie: resolved (fixed in 2.6.30.dfsg-3.1)
GHSA
GHSA-mq3q-3vmf-c9rw: The xmlCurrentChar function in libxml2 before 2
ghsa_unreviewed·2022-05-01
CVE-2007-6284 [MEDIUM] GHSA-mq3q-3vmf-c9rw: The xmlCurrentChar function in libxml2 before 2
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
OSV
CVE-2007-6284: The xmlCurrentChar function in libxml2 before 2
osv·2008-01-12·CVSS 5.0
CVE-2007-6284 [MEDIUM] CVE-2007-6284: The xmlCurrentChar function in libxml2 before 2
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=202628http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000009.htmlhttp://mail.gnome.org/archives/xml/2008-January/msg00036.htmlhttp://secunia.com/advisories/28439http://secunia.com/advisories/28444http://secunia.com/advisories/28450http://secunia.com/advisories/28452http://secunia.com/advisories/28458http://secunia.com/advisories/28466http://secunia.com/advisories/28470http://secunia.com/advisories/28475http://secunia.com/advisories/28636http://secunia.com/advisories/28716http://secunia.com/advisories/28740http://secunia.com/advisories/29591http://secunia.com/advisories/31074http://security.gentoo.org/glsa/glsa-200801-20.xmlhttp://securitytracker.com/id?1019181http://sunsolve.sun.com/search/document.do?assetkey=1-26-103201-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201514-1http://support.avaya.com/elmodocs2/security/ASA-2008-047.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-050.htmhttp://www.debian.org/security/2008/dsa-1461http://www.mandriva.com/security/advisories?name=MDVSA-2008:010http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0032.htmlhttp://www.securityfocus.com/archive/1/486410/100/0/threadedhttp://www.securityfocus.com/archive/1/490306/100/0/threadedhttp://www.securityfocus.com/bid/27248http://www.vupen.com/english/advisories/2008/0117http://www.vupen.com/english/advisories/2008/0144http://www.vupen.com/english/advisories/2008/1033/referenceshttp://www.vupen.com/english/advisories/2008/2094/referenceshttp://www.xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=425927https://issues.rpath.com/browse/RPL-2121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11594https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5216https://usn.ubuntu.com/569-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00379.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00396.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=202628http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000009.htmlhttp://mail.gnome.org/archives/xml/2008-January/msg00036.htmlhttp://secunia.com/advisories/28439http://secunia.com/advisories/28444http://secunia.com/advisories/28450http://secunia.com/advisories/28452http://secunia.com/advisories/28458http://secunia.com/advisories/28466http://secunia.com/advisories/28470http://secunia.com/advisories/28475http://secunia.com/advisories/28636http://secunia.com/advisories/28716http://secunia.com/advisories/28740http://secunia.com/advisories/29591http://secunia.com/advisories/31074http://security.gentoo.org/glsa/glsa-200801-20.xmlhttp://securitytracker.com/id?1019181http://sunsolve.sun.com/search/document.do?assetkey=1-26-103201-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201514-1http://support.avaya.com/elmodocs2/security/ASA-2008-047.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-050.htmhttp://www.debian.org/security/2008/dsa-1461http://www.mandriva.com/security/advisories?name=MDVSA-2008:010http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0032.htmlhttp://www.securityfocus.com/archive/1/486410/100/0/threadedhttp://www.securityfocus.com/archive/1/490306/100/0/threadedhttp://www.securityfocus.com/bid/27248http://www.vupen.com/english/advisories/2008/0117http://www.vupen.com/english/advisories/2008/0144http://www.vupen.com/english/advisories/2008/1033/referenceshttp://www.vupen.com/english/advisories/2008/2094/referenceshttp://www.xmlsoft.org/news.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=425927https://issues.rpath.com/browse/RPL-2121https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11594https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5216https://usn.ubuntu.com/569-1/https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00379.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00396.html
2008-01-12
Published