Saturday, November 13, 2010

libxml2: buffer overflow vulnerability

Users of libxml2 please be advised of a buffer overflow vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-1016-1: [USN-1016-1] libxml2 buffer overflow vulnerability
Details follow:



Bui Quang Minh discovered that libxml2 did not properly process XPath

namespaces and attributes. If an application using libxml2 opened a

specially crafted XML file, an attacker could cause a denial of service or

possibly execute code as the user invoking the program.


Read more at www.criticalwatch.com
 

No comments:

Post a Comment