CVE-2011-3919
published 2012-01-07CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.42%
82.4th percentile
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 6.0 | 6.0 |
| apple | mac_os_x | < 10.7.4 | 10.7.4 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.7.8.dfsg-7 (bookworm) | libxml2 2.7.8.dfsg-7 (bookworm) |
| chrome | < 16.0.912.75 | 16.0.912.75 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_server | — | — |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-7 | 2.7.8.dfsg-7 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-7 | 2.7.8.dfsg-7 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-7 | 2.7.8.dfsg-7 |
| xmlsoft | libxml2 | >= 0 < 2.7.8.dfsg-7 | 2.7.8.dfsg-7 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu9.3CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c47-25cj-whfq: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16
ghsa_unreviewed·2022-05-13
CVE-2011-3919 [HIGH] CWE-787 GHSA-7c47-25cj-whfq: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16
osv·2012-01-07·CVSS 7.5
CVE-2011-3919 [HIGH] CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2012-01-19·CVSS 9.3
CVE-2011-0216 [CRITICAL] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Applications using libxml2 could be made to crash or run programs as your
login if they opened a specially crafted file.
It was discovered that libxml2 contained an off by one error. If a user or
application linked against libxml2 were tricked into opening a specially
crafted XML file, an attacker could cause the application to crash or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2011-0216)
It was discovered that libxml2 is vulnerable to double-free conditions
when parsing certain XML documents. This could allow a remote attacker to
cause a denial of service. (CVE-2011-2821, CVE-2011-2834)
It was discovered that libxml2 did not properly detect end of file when
parsing certain XML documents. An attack
Red Hat
libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
vendor_redhat·2012-01-06·CVSS 7.5
CVE-2011-3919 [HIGH] CWE-122 libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue affected the versions of libxml2 as shipped with Red Hat Enterprise Linux 4, 5 and 6 and has been addressed via RHSA-2012:0016, RHSA-2012:0017 and RHSA-2012:0018 respectively.
Debian
CVE-2011-3919: libxml2 - Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912....
vendor_debian·2011·CVSS 7.5
CVE-2011-3919 [HIGH] CVE-2011-3919: libxml2 - Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912....
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 2.7.8.dfsg-7)
bullseye: resolved (fixed in 2.7.8.dfsg-7)
forky: resolved (fixed in 2.7.8.dfsg-7)
sid: resolved (fixed in 2.7.8.dfsg-7)
trixie: resolved (fixed in 2.7.8.dfsg-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3919 CVE-2011-3905 CVE-2011-2834 libxml2 various flaws [fedora-all]
bugzilla·2012-01-06·CVSS 6.8
CVE-2011-3919 [MEDIUM] CVE-2011-3919 CVE-2011-3905 CVE-2011-2834 libxml2 various flaws [fedora-all]
CVE-2011-3919 CVE-2011-3905 CVE-2011-2834 libxml2 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=securit
Bugzilla
CVE-2011-3919 libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
bugzilla·2012-01-05·CVSS 7.5
CVE-2011-3919 [HIGH] CVE-2011-3919 libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
CVE-2011-3919 libxml2: Heap-based buffer overflow when decoding an entity reference with a long name
A heap-based buffer overflow was found in the way libxml2 decoded an entity reference with a long name. A remote attacker could provide a specially-crafted XML file, which once opened in an application linked against libxml would cause that application to crash, or, potentially, execute arbitrary code with the privileges of the user running the application.
Reference: http://googlechromereleases.blogspot.com/2012/01/stable-channel-update.html
Patch: http://git.gnome.org/browse/libxml2/commit/?id=5bd3c061823a8499b27422aee04ea20aae24f03e
Discussion:
Created libxml2 tracking bugs for this issue
Affects: fedora-all [bug 772122]
---
This issue has been addressed in following products:
Re
Bugzilla
CVE-2011-0216 CVE-2011-3905 CVE-2011-3919 mingw32-libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
bugzilla·2011-11-22·CVSS 9.3
CVE-2011-0216 [CRITICAL] CVE-2011-0216 CVE-2011-3905 CVE-2011-3919 mingw32-libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
CVE-2011-0216 CVE-2011-3905 CVE-2011-3919 mingw32-libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission li
Bugzilla
CVE-2011-0216 libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
bugzilla·2011-11-22·CVSS 9.3
CVE-2011-0216 [CRITICAL] CVE-2011-0216 libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
CVE-2011-0216 libxml2: Off-by-one error leading to heap-based buffer overflow in encoding [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
http://code.google.com/p/chromium/issues/detail?id=107128http://googlechromereleases.blogspot.com/2012/01/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/47449http://secunia.com/advisories/55568http://support.apple.com/kb/HT5281http://support.apple.com/kb/HT5503http://www.debian.org/security/2012/dsa-2394http://www.mandriva.com/security/advisories?name=MDVSA-2012:005http://www.securityfocus.com/bid/51300http://www.securitytracker.com/id?1026487https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14504http://code.google.com/p/chromium/issues/detail?id=107128http://googlechromereleases.blogspot.com/2012/01/stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0217.htmlhttp://secunia.com/advisories/47449http://secunia.com/advisories/55568http://support.apple.com/kb/HT5281http://support.apple.com/kb/HT5503http://www.debian.org/security/2012/dsa-2394http://www.mandriva.com/security/advisories?name=MDVSA-2012:005http://www.securityfocus.com/bid/51300http://www.securitytracker.com/id?1026487https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14504
2012-01-07
Published