CVE-2010-4494
published 2010-12-07CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.53%
93.8th percentile
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | 2.1.0 – 2.4.3 | — |
| apache | openoffice | >= 3.0.0 < 3.3.0 | 3.3.0 |
| apple | iphone_os | < 4.3.0 | 4.3.0 |
| apple | itunes | < 10.2 | 10.2 |
| apple | mac_os_x | < 10.6.7 | 10.6.7 |
| apple | safari | < 5.0.4 | 5.0.4 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.7.8.dfsg-2 (bookworm) | libxml2 2.7.8.dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome | < 8.0.552.215 | 8.0.552.215 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | suse_linux_enterprise_server | — | — |
| xmlsoft | libxml2 | <= 2.7.8 | — |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-2 | 2.7.8.dfsg-2 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-2 | 2.7.8.dfsg-2 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-2 | 2.7.8.dfsg-2 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-2 | 2.7.8.dfsg-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libxml2: double-free in XPath processing code
vendor_redhat·2010-11-17·CVSS 7.5
CVE-2010-4494 [HIGH] libxml2: double-free in XPath processing code
libxml2: double-free in XPath processing code
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Statement: This issue did not affect the versions of libxml and libxml2 as shipped with
Red Hat Enterprise Linux 3, and it did not affect the version of libxml2 as
shipped with Red Hat Enterprise Linux 4 and 5.
Package: libxml2 (Red Hat Enterprise Linux 4) - Not affected
Package: libxml2 (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2010-4494: libxml2 - Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google...
vendor_debian·2010·CVSS 7.5
CVE-2010-4494 [HIGH] CVE-2010-4494: libxml2 - Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google...
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Scope: local
bookworm: resolved (fixed in 2.7.8.dfsg-2)
bullseye: resolved (fixed in 2.7.8.dfsg-2)
forky: resolved (fixed in 2.7.8.dfsg-2)
sid: resolved (fixed in 2.7.8.dfsg-2)
trixie: resolved (fixed in 2.7.8.dfsg-2)
GHSA
GHSA-3m5c-7hqx-55x7: Double free vulnerability in libxml2 2
ghsa_unreviewed·2022-05-13
CVE-2010-4494 [HIGH] CWE-415 GHSA-3m5c-7hqx-55x7: Double free vulnerability in libxml2 2
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
OSV
CVE-2010-4494: Double free vulnerability in libxml2 2
osv·2010-12-07·CVSS 7.5
CVE-2010-4494 [HIGH] CVE-2010-4494: Double free vulnerability in libxml2 2
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4494 libxml2: double-free in XPath processing code
bugzilla·2010-12-28·CVSS 7.5
CVE-2010-4494 [HIGH] CVE-2010-4494 libxml2: double-free in XPath processing code
CVE-2010-4494 libxml2: double-free in XPath processing code
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4494 to
the following vulnerability:
Name: CVE-2010-4494
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4494
Assigned: 20101207
Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=63444
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.html
Double free vulnerability in Google Chrome before 8.0.552.215 allows
remote attackers to cause a denial of service or possibly have
unspecified other impact via vectors related to XPath handling.
Upstream libxml2 patch:
http://git.gnome.org/browse/libxml2/commit/?id=df83c17e5a2646bd923f75e5e507bc80d73c9722
Discussion:
Statement:
This issue did
Bugzilla
CVE-2010-4494 libxml2: Memory corruption (double-free) in XPath processing code [fedora-all]
bugzilla·2010-12-28·CVSS 7.5
CVE-2010-4494 [HIGH] CVE-2010-4494 libxml2: Memory corruption (double-free) in XPath processing code [fedora-all]
CVE-2010-4494 libxml2: Memory corruption (double-free) in XPath processing code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=665963
Please note: this issu
http://code.google.com/p/chromium/issues/detail?id=63444http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055775.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/40775http://secunia.com/advisories/42472http://secunia.com/advisories/42721http://secunia.com/advisories/42762http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2137http://www.mandriva.com/security/advisories?name=MDVSA-2010:260http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1749.htmlhttp://www.vupen.com/english/advisories/2010/3319http://www.vupen.com/english/advisories/2010/3336http://www.vupen.com/english/advisories/2011/0230https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11916http://code.google.com/p/chromium/issues/detail?id=63444http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055775.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/40775http://secunia.com/advisories/42472http://secunia.com/advisories/42721http://secunia.com/advisories/42762http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4564http://support.apple.com/kb/HT4566http://support.apple.com/kb/HT4581http://www.debian.org/security/2010/dsa-2137http://www.mandriva.com/security/advisories?name=MDVSA-2010:260http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1749.htmlhttp://www.vupen.com/english/advisories/2010/3319http://www.vupen.com/english/advisories/2010/3336http://www.vupen.com/english/advisories/2011/0230https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11916
2010-12-07
Published