CVE-2010-4008
Last modified
CVE-2010-4008 is a vulnerability of currently unknown severity. libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Chrome | < 7.0.517.44 | — | |
| Apple | Itunes | < 10.2 | — |
| Apple | Safari | < 5.0.4 | — |
| Apple | Iphone Os | < 4.2 | — |
| Apple | Mac Os X | < 10.6.7 | — |
| Xmlsoft | Libxml2 | < 2.7.8 | — |
| Debian | Debian Linux | 5.0 | — |
| Debian | Debian Linux | 6.0 | — |
| Canonical | Ubuntu Linux | 6.06 | — |
| Canonical | Ubuntu Linux | 8.04 | — |
| Canonical | Ubuntu Linux | 9.10 | — |
| Canonical | Ubuntu Linux | 10.04 | — |
| Canonical | Ubuntu Linux | 10.10 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server Eus | 6.3 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Opensuse | Opensuse | 11.1 | — |
| Opensuse | Opensuse | 11.2 | — |
| Opensuse | Opensuse | 11.3 | — |
| Suse | Suse Linux Enterprise Server | 10 | Sp3 |
| Suse | Suse Linux Enterprise Server | 11 | — |
| Apache | Openoffice | >= 2.0.0, <= 2.4.3 | — |
| Apache | Openoffice | >= 3.0.0, < 3.3.0 | — |
References
- http://code.google.com/p/chromium/issues/detail?id=58731Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlMailing List, Third Party Advisory
- http://mail.gnome.org/archives/xml/2010-November/msg00015.htmlMailing List, Release Notes, Vendor Advisory
- http://marc.info/?l=bugtraq&m=130331363227777&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0217.htmlThird Party Advisory
- http://secunia.com/advisories/40775Third Party Advisory
- http://secunia.com/advisories/42109Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42175Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/42429Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://support.apple.com/kb/HT4554Third Party Advisory
- http://support.apple.com/kb/HT4566Third Party Advisory
- http://support.apple.com/kb/HT4581Third Party Advisory
- http://www.debian.org/security/2010/dsa-2128Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243Third Party Advisory
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1749.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44779Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1016-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Permissions Required
- http://www.vupen.com/english/advisories/2010/3076Permissions Required
- http://www.vupen.com/english/advisories/2010/3100Permissions Required
- http://www.vupen.com/english/advisories/2011/0230Permissions Required
- http://code.google.com/p/chromium/issues/detail?id=58731Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlMailing List, Third Party Advisory
- http://mail.gnome.org/archives/xml/2010-November/msg00015.htmlMailing List, Release Notes, Vendor Advisory
- http://marc.info/?l=bugtraq&m=130331363227777&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0217.htmlThird Party Advisory
- http://secunia.com/advisories/40775Third Party Advisory
- http://secunia.com/advisories/42109Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42175Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/42429Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://support.apple.com/kb/HT4554Third Party Advisory
- http://support.apple.com/kb/HT4566Third Party Advisory
- http://support.apple.com/kb/HT4581Third Party Advisory
- http://www.debian.org/security/2010/dsa-2128Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243Third Party Advisory
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1749.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44779Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1016-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Permissions Required
- http://www.vupen.com/english/advisories/2010/3076Permissions Required
- http://www.vupen.com/english/advisories/2010/3100Permissions Required
- http://www.vupen.com/english/advisories/2011/0230Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4008?
How severe is CVE-2010-4008?
How do I fix CVE-2010-4008?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3999gnc-test-env in GnuCash 2.3.15 and earlier places a zero-len…
- CVE-2010-4000gnome-shell in GNOME Shell 2.31.5 places a zero-length direc…
- CVE-2010-4001GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length…
- CVE-2010-4005The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy …
- CVE-2010-4006Multiple SQL injection vulnerabilities in search.php in WSN …
- CVE-2010-4007Oracle Mojarra uses an encrypted View State without a Messag…
- CVE-2010-4009Integer overflow in Apple QuickTime before 7.6.9 allows remo…
- CVE-2010-4010Integer signedness error in Apple Type Services (ATS) in App…
- CVE-2010-4011Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly ma…
- CVE-2010-4012Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G an…
- CVE-2010-4013Format string vulnerability in PackageKit in Apple Mac OS X …
- CVE-2010-4014Rejected reason: This candidate is unused by its CNA.
Are you affected by CVE-2010-4008?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
