CVE-2010-4008
Last modified
CVE-2010-4008 is a vulnerability of currently unknown severity. libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Chrome | < 7.0.517.44 | — | |
| Apple | Itunes | < 10.2 | — |
| Apple | Safari | < 5.0.4 | — |
| Apple | Iphone Os | < 4.2 | — |
| Apple | Mac Os X | < 10.6.7 | — |
| Xmlsoft | Libxml2 | < 2.7.8 | — |
| Debian | Debian Linux | 5.0 | — |
| Debian | Debian Linux | 6.0 | — |
| Canonical | Ubuntu Linux | 6.06 | — |
| Canonical | Ubuntu Linux | 8.04 | — |
| Canonical | Ubuntu Linux | 9.10 | — |
| Canonical | Ubuntu Linux | 10.04 | — |
| Canonical | Ubuntu Linux | 10.10 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server Eus | 6.3 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Opensuse | Opensuse | 11.1 | — |
| Opensuse | Opensuse | 11.2 | — |
| Opensuse | Opensuse | 11.3 | — |
| Suse | Suse Linux Enterprise Server | 10 | Sp3 |
| Suse | Suse Linux Enterprise Server | 11 | — |
| Apache | Openoffice | >= 2.0.0, <= 2.4.3 | — |
| Apache | Openoffice | >= 3.0.0, < 3.3.0 | — |
References
- http://code.google.com/p/chromium/issues/detail?id=58731Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlMailing List, Third Party Advisory
- http://mail.gnome.org/archives/xml/2010-November/msg00015.htmlMailing List, Release Notes, Vendor Advisory
- http://marc.info/?l=bugtraq&m=130331363227777&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0217.htmlThird Party Advisory
- http://secunia.com/advisories/40775Third Party Advisory
- http://secunia.com/advisories/42109Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42175Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/42429Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://support.apple.com/kb/HT4554Third Party Advisory
- http://support.apple.com/kb/HT4566Third Party Advisory
- http://support.apple.com/kb/HT4581Third Party Advisory
- http://www.debian.org/security/2010/dsa-2128Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243Third Party Advisory
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1749.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44779Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1016-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Permissions Required
- http://www.vupen.com/english/advisories/2010/3076Permissions Required
- http://www.vupen.com/english/advisories/2010/3100Permissions Required
- http://www.vupen.com/english/advisories/2011/0230Permissions Required
- http://code.google.com/p/chromium/issues/detail?id=58731Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlMailing List, Third Party Advisory
- http://mail.gnome.org/archives/xml/2010-November/msg00015.htmlMailing List, Release Notes, Vendor Advisory
- http://marc.info/?l=bugtraq&m=130331363227777&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0217.htmlThird Party Advisory
- http://secunia.com/advisories/40775Third Party Advisory
- http://secunia.com/advisories/42109Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42175Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/42429Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://support.apple.com/kb/HT4554Third Party Advisory
- http://support.apple.com/kb/HT4566Third Party Advisory
- http://support.apple.com/kb/HT4581Third Party Advisory
- http://www.debian.org/security/2010/dsa-2128Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243Third Party Advisory
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1749.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44779Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1016-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Permissions Required
- http://www.vupen.com/english/advisories/2010/3076Permissions Required
- http://www.vupen.com/english/advisories/2010/3100Permissions Required
- http://www.vupen.com/english/advisories/2011/0230Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4008?
How severe is CVE-2010-4008?
How do I fix CVE-2010-4008?
Are you affected by CVE-2010-4008?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
