Libxml2 'xmlxptrevalxptrpart () 'function single-byte Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
XMLSoft Libxml2 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53597
The libxml package provides a function library that allows users to manipulate XML files, including reading, modifying, and writing XML and HTML files.
Libxml2 "xmlXPtrEvalXPtrPart ()" function (pointer. c) A single-byte error exists, which can be exploited to trigger out-of-boundary writing, causing the application of the affected database to crash and run arbitrary code.
<* Source: J & #195; & #188; ri Aedla
Jüri Aedla
Link: http://secunia.com/advisories/49177/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XMLSoft
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.xmlsoft.org/