CVE-2011-2834Double Free in Google Chrome

CWE-415Double Free10 documents7 sources
Severity
6.8MEDIUMNVD
EPSS
2.9%
top 13.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 13

Description

Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages8 packages

NVDgoogle/chrome< 14.0.835.163
debiandebian/libxml2< libxml2 2.7.8.dfsg-5 (bookworm)
Debianxmlsoft/libxml2< 2.7.8.dfsg-5+3
NVDapple/mac_os_x< 10.7.4
NVDapple/iphone_os< 6.0

Also affects: Debian Linux 5.0, 6.0, 7.0, Enterprise Linux 6.3

🔴Vulnerability Details

2
GHSA
GHSA-r39r-m3xh-jh67: Double free vulnerability in libxml2, as used in Google Chrome before 142022-05-13
OSV
CVE-2011-2834: Double free vulnerability in libxml2, as used in Google Chrome before 142011-09-19

📋Vendor Advisories

3
Ubuntu
libxml2 vulnerabilities2012-01-19
Red Hat
libxml2: double-free caused by malformed XPath expression in XSLT2011-10-11
Debian
CVE-2011-2834: libxml2 - Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.1...2011

💬Community

4
Bugzilla
CVE-2011-3919 CVE-2011-3905 CVE-2011-2834 libxml2 various flaws [fedora-all]2012-01-06
Bugzilla
CVE-2011-0216 CVE-2011-3905 CVE-2011-3919 mingw32-libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]2011-11-22
Bugzilla
CVE-2011-0216 libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]2011-11-22
Bugzilla
CVE-2011-2834 libxml2: double-free caused by malformed XPath expression in XSLT2011-09-05
CVE-2011-2834 — Double Free in Google Chrome | cvebase