CVE-2010-4008
published 2010-11-17CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.13%
86.4th percentile
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | 2.0.0 – 2.4.3 | — |
| apache | openoffice | >= 3.0.0 < 3.3.0 | 3.3.0 |
| apple | iphone_os | < 4.2 | 4.2 |
| apple | itunes | < 10.2 | 10.2 |
| apple | mac_os_x | < 10.6.7 | 10.6.7 |
| apple | safari | < 5.0.4 | 5.0.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.7.8.dfsg-1 (bookworm) | libxml2 2.7.8.dfsg-1 (bookworm) |
| chrome | < 7.0.517.44 | 7.0.517.44 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | suse_linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_server | — | — |
| xmlsoft | libxml2 | < 2.7.8 | 2.7.8 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-472j-j78w-732c: libxml2 before 2
ghsa_unreviewed·2022-05-13
CVE-2010-4008 [MEDIUM] CWE-119 GHSA-472j-j78w-732c: libxml2 before 2
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
OSV
CVE-2010-4008: libxml2 before 2
osv·2010-11-17·CVSS 4.3
CVE-2010-4008 [MEDIUM] CVE-2010-4008: libxml2 before 2
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2010-11-10
CVE-2010-4008 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to crash or run programs as your login if it opened a
specially crafted file.
Bui Quang Minh discovered that libxml2 did not properly process XPath
namespaces and attributes. If an application using libxml2 opened a
specially crafted XML file, an attacker could cause a denial of service or
possibly execute code as the user invoking the program.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
vendor_redhat·2010-11-04·CVSS 4.3
CVE-2010-4008 [MEDIUM] CWE-476 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Statement: This issue did not affect the versions of libxml and libxml2 as shipped with Red Hat Enterprise Linux 3, and it did not affect the version of libxml2 as shipped with Red Hat Enterprise Linux 4.
Package: libxml2 (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-4008: libxml2 - libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5...
vendor_debian·2010·CVSS 4.3
CVE-2010-4008 [MEDIUM] CVE-2010-4008: libxml2 - libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5...
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Scope: local
bookworm: resolved (fixed in 2.7.8.dfsg-1)
bullseye: resolved (fixed in 2.7.8.dfsg-1)
forky: resolved (fixed in 2.7.8.dfsg-1)
sid: resolved (fixed in 2.7.8.dfsg-1)
trixie: resolved (fixed in 2.7.8.dfsg-1)
No detection rules found.
Bugzilla
CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis [fedora-all]
bugzilla·2010-11-10·CVSS 4.3
CVE-2010-4008 [MEDIUM] CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis [fedora-all]
CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=645
Bugzilla
CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
bugzilla·2010-10-21·CVSS 4.3
CVE-2010-4008 [MEDIUM] CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
CVE-2010-4008 libxml2: Crash (stack frame overflow or NULL pointer dereference) by traversal of XPath axis
A security flaw was found in the way libxml traversed XPath axis
of particular Extensible Markup Language (XML) file and tested
namespace / attribute context nodes for their validity. A remote
attacker could provide a specially-crafted XML file, which once
opened with an application linked against libxml would cause that
application to crash (due stack frame overflow and / or with NULL
pointer dereference on some architectures).
Chrome bug report (not accessible for public audience):
[1] http://code.google.com/p/chromium/issues/detail?id=58731
Upstream changesets:
[2] http://git.gnome.org/browse/libxml2/commit/?id=91d19754d46acd4a639a8b9e31f50f31c78f8c9c
[3] http://git.gnome.org/br
http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/http://code.google.com/p/chromium/issues/detail?id=58731http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://mail.gnome.org/archives/xml/2010-November/msg00015.htmlhttp://marc.info/?l=bugtraq&m=130331363227777&w=2http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/40775http://secunia.com/advisories/42109http://secunia.com/advisories/42175http://secunia.com/advisories/42314http://secunia.com/advisories/42429http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2128http://www.mandriva.com/security/advisories?name=MDVSA-2010:243http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1749.htmlhttp://www.securityfocus.com/bid/44779http://www.ubuntu.com/usn/USN-1016-1http://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2010/3076http://www.vupen.com/english/advisories/2010/3100http://www.vupen.com/english/advisories/2011/0230https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/http://code.google.com/p/chromium/issues/detail?id=58731http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://mail.gnome.org/archives/xml/2010-November/msg00015.htmlhttp://marc.info/?l=bugtraq&m=130331363227777&w=2http://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/40775http://secunia.com/advisories/42109http://secunia.com/advisories/42175http://secunia.com/advisories/42314http://secunia.com/advisories/42429http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2128http://www.mandriva.com/security/advisories?name=MDVSA-2010:243http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1749.htmlhttp://www.securityfocus.com/bid/44779http://www.ubuntu.com/usn/USN-1016-1http://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2010/3076http://www.vupen.com/english/advisories/2010/3100http://www.vupen.com/english/advisories/2011/0230https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148
2010-11-17
Published