FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-2877

This CVE name corresponds to:

Entered Topic
2013-07-10 chromium -- multiple vulnerabilities
libxml2 -- lack of end-of-document check DoS

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-2877
Phase Assigned(20130411)

Description

parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.

References

Source Reference
BUGTRAQ 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
FULLDISC 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
CONFIRM ftp://xmlsoft.org/libxml2/libxml2-2.9.0.tar.gz
CONFIRM http://git.chromium.org/gitweb/?p=chromium/chromium.git;a=commit;h=e5d7f7e5dc21d3ae7be3cbb949ac4d8701e06de1
CONFIRM http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html
CONFIRM https://code.google.com/p/chromium/issues/detail?id=229019
CONFIRM http://www.vmware.com/security/advisories/VMSA-2014-0012.html
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
DEBIAN DSA-2724
DEBIAN DSA-2779
SUSE openSUSE-SU-2013:1221
SUSE openSUSE-SU-2013:1246
SUSE SUSE-SU-2013:1627
UBUNTU USN-1904-1
UBUNTU USN-1904-2
SECUNIA 54172
SECUNIA 55568