Lucene search

K
osvGoogleOSV:DSA-2128-1
HistoryDec 01, 2010 - 12:00 a.m.

libxml2 - potential code execution

2010-12-0100:00:00
Google
osv.dev
16

0.002 Low

EPSS

Percentile

54.2%

Bui Quang Minh discovered that libxml2, a library for parsing and
handling XML data files, does not well process a malformed XPATH,
causing crash and allowing arbitrary code execution.

For the stable distribution (lenny), this problem has been fixed in
version 2.6.32.dfsg-5+lenny2.

For the testing (squeeze) and unstable (sid) distribution, this problem
has been fixed in version 2.7.8.dfsg-1.

We recommend that you upgrade your libxml2 package.