Description
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-fx83-qvvj-7h25: parser↗2022-05-17 ▶ CVEListCVE-2013-2877: parser↗2013-07-10 ▶ OSVCVE-2013-2877: parser↗2013-07-10 ▶ 📋Vendor Advisories
3Ubuntulibxml2 vulnerabilities↗2013-07-15 ▶ Red Hatlibxml2: Out-of-bounds read via a document that ends abruptly↗2013-07-09 ▶ DebianCVE-2013-2877: libxml2 - parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 a...↗2013 ▶ 💬Community
2BugzillaCVE-2013-2877 libxml2: Out-of-bounds read via a document that ends abruptly↗2013-07-10 ▶ Bugzillalibxml2: CVE-2013-2877 libxml2: Out-of-bounds read via a document that ends abruptly [fedora-17]↗2013-07-10 ▶