7.5
CVSSv2

CVE-2013-1969

Published: 25/04/2013 Updated: 21/06/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2 2.9.0

Vendor Advisories

libxml2 could be made to crash or run programs if it opened a specially crafted file ...