Описание
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 62.0.3202.62-0ubuntu0.17.10.1380 |
| bionic | released | 62.0.3202.62-0ubuntu0.17.10.1380 |
| cosmic | released | 62.0.3202.62-0ubuntu0.17.10.1380 |
| devel | released | 62.0.3202.62-0ubuntu0.17.10.1380 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [62.0.3202.62-0ubuntu0.14.04.1204]] |
| precise/esm | DNE | |
| trusty | released | 62.0.3202.62-0ubuntu0.14.04.1204 |
| trusty/esm | DNE | trusty was released [62.0.3202.62-0ubuntu0.14.04.1204] |
| upstream | released | 62.0.3202.62 |
| xenial | released | 62.0.3202.62-0ubuntu0.16.04.1308 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | |
| bionic | released | 2.9.4+dfsg1-6.1ubuntu1 |
| cosmic | released | 2.9.4+dfsg1-6.1ubuntu1 |
| devel | released | 2.9.4+dfsg1-6.1ubuntu1 |
| esm-infra-legacy/trusty | ignored | |
| esm-infra/bionic | released | 2.9.4+dfsg1-6.1ubuntu1 |
| esm-infra/xenial | ignored | |
| precise/esm | ignored | |
| trusty | ignored | |
| trusty/esm | ignored |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]] |
| esm-infra/xenial | ignored | Ubuntu touch end-of-life |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [Ubuntu touch end-of-life] |
| upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in ...
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
Уязвимость компонента xmlmemory.c программного обеспечения для анализа XML-документов libxml2, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3