CVE-2008-3529
UnknownEPSS 23.37%
Last modified
CVE-2008-3529 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.. EPSS estimates a 23.37% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | < 2.7.0 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 8.10 |
| Canonical | Ubuntu Linux | 9.04 |
| Apple | Safari | < 4.0 |
| Apple | Safari | >= 3.2.0, < 3.2.3 |
| Apple | Iphone Os | < 3.0 |
| Apple | Mac Os X | < 10.5.7 |
| Apple | Mac Os X | 10.5.7 |
References
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/31558Third Party Advisory
- http://secunia.com/advisories/31855Third Party Advisory
- http://secunia.com/advisories/31860Third Party Advisory
- http://secunia.com/advisories/31868Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://secunia.com/advisories/32265Third Party Advisory
- http://secunia.com/advisories/32280Third Party Advisory
- http://secunia.com/advisories/32807Third Party Advisory
- http://secunia.com/advisories/32974Third Party Advisory
- http://secunia.com/advisories/33715Third Party Advisory
- http://secunia.com/advisories/33722Third Party Advisory
- http://secunia.com/advisories/35056Third Party Advisory
- http://secunia.com/advisories/35074Third Party Advisory
- http://secunia.com/advisories/35379Third Party Advisory
- http://secunia.com/advisories/36173Third Party Advisory
- http://secunia.com/advisories/36235Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-06.xmlThird Party Advisory
- http://securitytracker.com/id?1020855Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT3549Third Party Advisory
- http://support.apple.com/kb/HT3550Third Party Advisory
- http://support.apple.com/kb/HT3613Third Party Advisory
- http://support.apple.com/kb/HT3639Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-400.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-025.htmThird Party Advisory
- http://www.debian.org/security/2008/dsa-1654Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0884.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0886.htmlThird Party Advisory
- http://www.securityfocus.com/bid/31126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-815-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/2822Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1297Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1298Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1522Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1621Third Party Advisory
- http://xmlsoft.org/news.htmlRelease Notes, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=461015Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45085Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/644-1/Third Party Advisory
- https://www.exploit-db.com/exploits/8798Exploit, Third Party Advisory, VDB Entry
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/31558Third Party Advisory
- http://secunia.com/advisories/31855Third Party Advisory
- http://secunia.com/advisories/31860Third Party Advisory
- http://secunia.com/advisories/31868Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://secunia.com/advisories/32265Third Party Advisory
- http://secunia.com/advisories/32280Third Party Advisory
- http://secunia.com/advisories/32807Third Party Advisory
- http://secunia.com/advisories/32974Third Party Advisory
- http://secunia.com/advisories/33715Third Party Advisory
- http://secunia.com/advisories/33722Third Party Advisory
- http://secunia.com/advisories/35056Third Party Advisory
- http://secunia.com/advisories/35074Third Party Advisory
- http://secunia.com/advisories/35379Third Party Advisory
- http://secunia.com/advisories/36173Third Party Advisory
- http://secunia.com/advisories/36235Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200812-06.xmlThird Party Advisory
- http://securitytracker.com/id?1020855Third Party Advisory, VDB Entry
- http://support.apple.com/kb/HT3549Third Party Advisory
- http://support.apple.com/kb/HT3550Third Party Advisory
- http://support.apple.com/kb/HT3613Third Party Advisory
- http://support.apple.com/kb/HT3639Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-400.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-025.htmThird Party Advisory
- http://www.debian.org/security/2008/dsa-1654Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0884.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0886.htmlThird Party Advisory
- http://www.securityfocus.com/bid/31126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-815-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/2822Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1297Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1298Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1522Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1621Third Party Advisory
- http://xmlsoft.org/news.htmlRelease Notes, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=461015Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45085Third Party Advisory, VDB Entry
- https://usn.ubuntu.com/644-1/Third Party Advisory
- https://www.exploit-db.com/exploits/8798Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3529?
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
How severe is CVE-2008-3529?
Severity scoring for CVE-2008-3529 is pending analysis. The EPSS model estimates a 23.37% probability of exploitation in the next 30 days.
How do I fix CVE-2008-3529?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2008-3529?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
