6.8
CVSSv2

CVE-2012-5134

Published: 28/11/2012 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and previous versions, as used in Google Chrome prior to 23.0.1271.91 and other products, allows remote malicious users to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 23.0.1271.87

google chrome 23.0.1271.58

xmlsoft libxml2 2.2.0

xmlsoft libxml2 2.2.2

google chrome 23.0.1271.19

google chrome 23.0.1271.51

xmlsoft libxml2 2.4.30

xmlsoft libxml2 2.6.16

xmlsoft libxml2 1.8.0

xmlsoft libxml2 1.8.16

xmlsoft libxml2 2.6.32

xmlsoft libxml2 2.1.0

xmlsoft libxml2 2.4.19

xmlsoft libxml2 2.4.7

xmlsoft libxml2 2.4.17

xmlsoft libxml2 2.2.9

google chrome 23.0.1271.45

google chrome 23.0.1271.18

xmlsoft libxml2 2.3.6

xmlsoft libxml2 2.6.26

google chrome 23.0.1271.17

xmlsoft libxml2 2.6.11

xmlsoft libxml2 1.7.1

xmlsoft libxml2 2.7.2

xmlsoft libxml2

xmlsoft libxml2 2.4.21

xmlsoft libxml2 2.4.20

xmlsoft libxml2 2.3.7

xmlsoft libxml2 2.6.17

xmlsoft libxml2 2.2.4

xmlsoft libxml2 2.4.25

xmlsoft libxml2 2.4.24

google chrome 23.0.1271.8

xmlsoft libxml2 2.5.0

xmlsoft libxml2 2.4.6

google chrome 23.0.1271.61

xmlsoft libxml2 2.4.12

xmlsoft libxml2 2.3.8

google chrome 23.0.1271.86

google chrome 23.0.1271.23

google chrome 23.0.1271.12

xmlsoft libxml2 1.8.5

xmlsoft libxml2 2.6.27

google chrome 23.0.1271.49

google chrome 23.0.1271.0

xmlsoft libxml2 2.3.13

google chrome 23.0.1271.1

xmlsoft libxml2 2.3.14

google chrome 23.0.1271.3

xmlsoft libxml2 2.1.1

xmlsoft libxml2 2.2.6

google chrome 23.0.1271.6

google chrome 23.0.1271.10

xmlsoft libxml2 2.2.10

xmlsoft libxml2 2.4.13

google chrome 23.0.1271.46

xmlsoft libxml2 2.3.1

xmlsoft libxml2 2.6.13

google chrome 23.0.1271.52

xmlsoft libxml2 2.7.7

xmlsoft libxml2 1.7.0

xmlsoft libxml2 2.6.7

xmlsoft libxml2 2.6.14

xmlsoft libxml2 2.4.27

xmlsoft libxml2 2.4.18

xmlsoft libxml2 2.5.7

google chrome 23.0.1271.54

google chrome 23.0.1271.15

xmlsoft libxml2 2.3.0

xmlsoft libxml2 2.4.10

xmlsoft libxml2 1.8.10

xmlsoft libxml2 1.8.13

xmlsoft libxml2 2.4.26

google chrome 23.0.1271.88

google chrome 23.0.1271.39

xmlsoft libxml2 2.5.8

google chrome 23.0.1271.85

xmlsoft libxml2 2.4.28

xmlsoft libxml2 2.3.3

google chrome 23.0.1271.55

xmlsoft libxml2 2.2.8

xmlsoft libxml2 2.4.9

xmlsoft libxml2 1.8.2

xmlsoft libxml2 2.4.5

google chrome 23.0.1271.57

xmlsoft libxml2 2.4.8

xmlsoft libxml2 1.8.9

xmlsoft libxml2 2.6.8

google chrome 23.0.1271.14

google chrome 23.0.1271.84

xmlsoft libxml2 1.7.2

xmlsoft libxml2 2.4.15

xmlsoft libxml2 2.4.11

xmlsoft libxml2 2.6.2

xmlsoft libxml2 2.9.0

xmlsoft libxml2 2.2.7

xmlsoft libxml2 2.2.5

xmlsoft libxml2 2.2.3

xmlsoft libxml2 2.4.22

xmlsoft libxml2 2.6.5

google chrome 23.0.1271.26

xmlsoft libxml2 2.6.4

google chrome 23.0.1271.31

xmlsoft libxml2 2.7.5

xmlsoft libxml2 2.6.18

xmlsoft libxml2 2.4.16

xmlsoft libxml2 2.5.11

google chrome 23.0.1271.24

xmlsoft libxml2 1.8.7

google chrome 23.0.1271.62

xmlsoft libxml2 2.3.5

google chrome 23.0.1271.2

xmlsoft libxml2 2.0.0

google chrome 23.0.1271.7

xmlsoft libxml2 2.3.10

xmlsoft libxml2 1.8.6

google chrome 23.0.1271.22

google chrome 23.0.1271.37

google chrome 23.0.1271.56

xmlsoft libxml2 2.4.2

google chrome 23.0.1271.40

google chrome 23.0.1271.30

xmlsoft libxml2 2.7.3

google chrome 23.0.1271.60

xmlsoft libxml2 2.3.4

xmlsoft libxml2 1.8.3

xmlsoft libxml2 2.6.1

xmlsoft libxml2 2.6.20

google chrome 23.0.1271.35

xmlsoft libxml2 2.7.1

xmlsoft libxml2 2.2.1

google chrome

xmlsoft libxml2 2.7.0

xmlsoft libxml2 2.7.6

xmlsoft libxml2 1.7.3

google chrome 23.0.1271.36

google chrome 23.0.1271.13

google chrome 23.0.1271.11

xmlsoft libxml2 2.3.9

xmlsoft libxml2 2.4.1

xmlsoft libxml2 2.4.23

xmlsoft libxml2 2.6.12

xmlsoft libxml2 2.6.0

google chrome 23.0.1271.21

google chrome 23.0.1271.33

google chrome 23.0.1271.64

xmlsoft libxml2 2.6.9

google chrome 23.0.1271.53

google chrome 23.0.1271.41

xmlsoft libxml2 2.5.4

xmlsoft libxml2 2.6.30

google chrome 23.0.1271.4

xmlsoft libxml2 1.8.1

google chrome 23.0.1271.20

xmlsoft libxml2 2.3.11

xmlsoft libxml2 2.4.3

google chrome 23.0.1271.16

xmlsoft libxml2 1.8.14

google chrome 23.0.1271.38

xmlsoft libxml2 2.7.4

xmlsoft libxml2 1.7.4

google chrome 23.0.1271.83

google chrome 23.0.1271.44

xmlsoft libxml2 1.8.4

xmlsoft libxml2 2.5.10

google chrome 23.0.1271.50

google chrome 23.0.1271.32

xmlsoft libxml2 2.3.12

xmlsoft libxml2 2.4.4

google chrome 23.0.1271.5

xmlsoft libxml2 2.4.14

xmlsoft libxml2 2.6.22

xmlsoft libxml2 2.3.2

xmlsoft libxml2 2.6.3

xmlsoft libxml2 2.2.11

xmlsoft libxml2 2.4.29

xmlsoft libxml2 2.6.6

apple iphone os 6.1.2

apple iphone os 3.0

apple iphone os 3.2

apple iphone os 3.1.3

apple iphone os 1.0.2

apple iphone os 4.3.2

apple iphone os 4.0.2

apple iphone os

apple iphone os 2.2

apple iphone os 1.1.1

apple iphone os 6.1.3

apple iphone os 5.1

apple iphone os 4.2.8

apple iphone os 6.0.2

apple iphone os 4.1

apple iphone os 2.0.0

apple iphone os 3.1.2

apple iphone os 3.0.1

apple iphone os 4.3.1

apple iphone os 4.2.5

apple iphone os 1.1.2

apple iphone os 3.1

apple iphone os 1.1.3

apple iphone os 1.1.0

apple iphone os 1.0.1

apple iphone os 2.1

apple iphone os 6.0

apple iphone os 4.3.5

apple iphone os 6.1

apple iphone os 4.2.1

apple iphone os 1.1.5

apple iphone os 4.0.1

apple iphone os 4.3.3

apple iphone os 5.0.1

apple iphone os 2.1.1

apple iphone os 1.1.4

apple iphone os 5.0

apple iphone os 1.0.0

apple iphone os 5.1.1

apple iphone os 2.0.2

apple iphone os 2.0

apple iphone os 2.0.1

apple iphone os 4.0

apple iphone os 4.3.0

apple iphone os 2.2.1

apple iphone os 3.2.1

apple iphone os 3.2.2

apple iphone os 6.0.1

Vendor Advisories

Synopsis Important: libxml2 security update Type/Severity Security Advisory: Important Topic Updated libxml2 packages that fix one security issue are now available forRed Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as havingimportant security impact A Common Vulner ...
Debian Bug report logs - #694521 libxml2: CVE-2012-5134 Package: libxml2; Maintainer for libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Source for libxml2 is src:libxml2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 27 Nov 2012 08:03:01 UTC Severi ...
Applications using libxml2 could be made to crash or run programs as your login if they opened a specially crafted file ...
Jueri Aedla discovered a buffer overflow in the libxml XML library, which could result in the execution of arbitrary code For the stable distribution (squeeze), this problem has been fixed in version 278dfsg-2+squeeze6 For the unstable distribution (sid), this problem has been fixed in version 280+dfsg1-7 We recommend that you upgrade your ...
A heap-based buffer underflow flaw was found in the way libxml2 decoded certain entities A remote attacker could provide a specially-crafted XML file that, when opened in an application linked against libxml2, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE- ...

Github Repositories

Program Vulnerability Repair via Inductive Inference

VulnFix VulnFix - An automated program repair technique for fixing security vulnerabilities via inductive inference VulnFix targets security vulnerabilities in C/C++ programs, such as buffer overflows, integer overflows, and NULL dereferences It works by first exploring the states at the patch location with a combination of input-level fuzzing and state-level mutations, an