5
CVSSv2

CVE-2012-0841

Published: 21/12/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libxml2 prior to 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via crafted XML data.

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2 2.2.0

xmlsoft libxml2 2.2.2

xmlsoft libxml2 2.4.30

xmlsoft libxml2 2.6.16

xmlsoft libxml2 1.8.0

xmlsoft libxml2 1.8.16

xmlsoft libxml2 2.6.32

xmlsoft libxml2 2.1.0

xmlsoft libxml2 2.6.29

xmlsoft libxml2 2.4.19

xmlsoft libxml2 2.4.7

xmlsoft libxml2 2.4.17

xmlsoft libxml2 2.2.9

xmlsoft libxml2 2.3.6

xmlsoft libxml2 2.6.26

xmlsoft libxml2 2.6.11

xmlsoft libxml2 1.7.1

xmlsoft libxml2 2.7.2

xmlsoft libxml2 2.4.21

xmlsoft libxml2 2.4.20

xmlsoft libxml2 2.3.7

xmlsoft libxml2 2.6.17

xmlsoft libxml2 2.2.4

xmlsoft libxml2 2.4.25

xmlsoft libxml2 2.4.24

xmlsoft libxml2 2.5.0

xmlsoft libxml2 2.4.6

xmlsoft libxml2 2.4.12

xmlsoft libxml2 2.3.8

xmlsoft libxml2 1.8.5

xmlsoft libxml2 2.6.27

xmlsoft libxml2 2.3.13

xmlsoft libxml2 2.3.14

xmlsoft libxml2 2.1.1

xmlsoft libxml2 2.2.6

xmlsoft libxml2 2.2.10

xmlsoft libxml2 2.4.13

xmlsoft libxml2 2.3.1

xmlsoft libxml2 2.6.13

xmlsoft libxml2 2.7.7

xmlsoft libxml2 1.7.0

xmlsoft libxml2 2.6.7

xmlsoft libxml2 2.6.14

xmlsoft libxml2 2.4.27

xmlsoft libxml2 2.4.18

xmlsoft libxml2 2.5.7

xmlsoft libxml2 2.3.0

xmlsoft libxml2 2.4.10

xmlsoft libxml2 1.8.10

xmlsoft libxml2 1.8.13

xmlsoft libxml2 2.4.26

xmlsoft libxml2 2.5.8

xmlsoft libxml2 2.4.28

xmlsoft libxml2 2.3.3

xmlsoft libxml2 2.2.8

xmlsoft libxml2 2.6.23

xmlsoft libxml2 2.4.9

xmlsoft libxml2 1.8.2

xmlsoft libxml2 2.4.5

xmlsoft libxml2 2.4.8

xmlsoft libxml2 1.8.9

xmlsoft libxml2 2.6.8

xmlsoft libxml2 1.7.2

xmlsoft libxml2 2.4.15

xmlsoft libxml2 2.4.11

xmlsoft libxml2 2.6.2

xmlsoft libxml2 2.2.7

xmlsoft libxml2 2.2.5

xmlsoft libxml2 2.2.3

xmlsoft libxml2 2.4.22

xmlsoft libxml2 2.6.5

xmlsoft libxml2 2.6.4

xmlsoft libxml2 2.7.5

xmlsoft libxml2 2.6.18

xmlsoft libxml2 2.4.16

xmlsoft libxml2 2.5.11

xmlsoft libxml2 2.6.24

xmlsoft libxml2 1.8.7

xmlsoft libxml2 2.3.5

xmlsoft libxml2 2.0.0

xmlsoft libxml2 2.3.10

xmlsoft libxml2 1.8.6

xmlsoft libxml2 2.4.2

xmlsoft libxml2 2.7.3

xmlsoft libxml2 2.3.4

xmlsoft libxml2 1.8.3

xmlsoft libxml2 2.6.1

xmlsoft libxml2 2.6.20

xmlsoft libxml2 2.6.31

xmlsoft libxml2 2.7.1

xmlsoft libxml2 2.2.1

xmlsoft libxml2 2.7.0

xmlsoft libxml2 2.6.21

xmlsoft libxml2 2.7.6

xmlsoft libxml2 1.7.3

xmlsoft libxml2 2.3.9

xmlsoft libxml2 2.4.1

xmlsoft libxml2 2.4.23

xmlsoft libxml2 2.6.12

xmlsoft libxml2 2.6.0

xmlsoft libxml2 2.6.25

xmlsoft libxml2 2.6.9

xmlsoft libxml2 2.5.4

xmlsoft libxml2 2.6.30

xmlsoft libxml2

xmlsoft libxml2 1.8.1

xmlsoft libxml2 2.3.11

xmlsoft libxml2 2.4.3

xmlsoft libxml2 1.8.14

xmlsoft libxml2 2.7.4

xmlsoft libxml2 1.7.4

xmlsoft libxml2 2.6.28

xmlsoft libxml2 1.8.4

xmlsoft libxml2 2.5.10

xmlsoft libxml2 2.3.12

xmlsoft libxml2 2.4.4

xmlsoft libxml2 2.4.14

xmlsoft libxml2 2.6.22

xmlsoft libxml2 2.3.2

xmlsoft libxml2 2.6.3

xmlsoft libxml2 2.2.11

xmlsoft libxml2 2.4.29

xmlsoft libxml2 2.6.6

apple iphone os 6.1.2

apple iphone os 3.0

apple iphone os 3.2

apple iphone os 3.1.3

apple iphone os 1.0.2

apple iphone os 4.3.2

apple iphone os 4.0.2

apple iphone os

apple iphone os 2.2

apple iphone os 1.1.1

apple iphone os 6.1.3

apple iphone os 5.1

apple iphone os 4.2.8

apple iphone os 6.0.2

apple iphone os 4.1

apple iphone os 2.0.0

apple iphone os 3.1.2

apple iphone os 3.0.1

apple iphone os 4.3.1

apple iphone os 4.2.5

apple iphone os 1.1.2

apple iphone os 3.1

apple iphone os 1.1.3

apple iphone os 1.1.0

apple iphone os 1.0.1

apple iphone os 2.1

apple iphone os 6.0

apple iphone os 4.3.5

apple iphone os 6.1

apple iphone os 4.2.1

apple iphone os 1.1.5

apple iphone os 4.0.1

apple iphone os 4.3.3

apple iphone os 5.0.1

apple iphone os 2.1.1

apple iphone os 1.1.4

apple iphone os 5.0

apple iphone os 1.0.0

apple iphone os 5.1.1

apple iphone os 2.0.2

apple iphone os 2.0

apple iphone os 2.0.1

apple iphone os 4.0

apple iphone os 4.3.0

apple iphone os 2.2.1

apple iphone os 3.2.1

apple iphone os 3.2.2

apple iphone os 6.0.1

Vendor Advisories

Synopsis Moderate: libxml2 security update Type/Severity Security Advisory: Moderate Topic Updated libxml2 packages that fix one security issue are now available forRed Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerabi ...
Debian Bug report logs - #660846 libxml2: CVE-2012-0841 computational DoS attack via hash collisions Package: src:libxml2; Maintainer for src:libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Nico Golde <nion@debianorg> Date: Wed, 22 Feb 2012 10:01:26 UTC Severity: grave T ...
libxml2 could be made to cause a denial of service by consuming excessive CPU resources ...
It was found that the hashing routine used by libxml2 arrays was susceptible to predictable hash collisions Sending a specially-crafted message to an XML service could result in longer processing time, which could lead to a denial of service To mitigate this issue, randomization has been added to the hashing function to reduce the chance of an at ...