Release date:
Updated on: 2013-04-23
Affected Systems:
XMLSoft Libxml2 2.9.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59265
CVE (CAN) ID: CVE-2013-1969, CVE-2013-1970
Libxml2 is an XML Parser and markup tool set.
Libxml2 2.9.0 and other versions have multiple post-release reuse vulnerabilities. The "htmlParseChunk ()" function and "xmldecl_done ()" function have post-release reuse errors, after being exploited, the released memory is indirectly referenced, resulting in DOS or arbitrary code execution.
<* Source: vendor
Link: https://git.gnome.org/browse/libxml2/commit? Id = de0cc20c29cb3f056062925395e0f68d2250a46f
Http://secunia.com/advisories/53061/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XMLSoft
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://git.gnome.org/browse/libxml2/snapshot/libxml2-de0cc20c29cb3f056062925395e0f68d2250a46f.zip
Https://git.gnome.org/browse/libxml2/snapshot/libxml2-de0cc20c29cb3f056062925395e0f68d2250a46f.tar.gz
Https://git.gnome.org/browse/libxml2/snapshot/libxml2-de0cc20c29cb3f056062925395e0f68d2250a46f.tar.bz2