MEDIUM · 4.3

CVE-2010-4008

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressio...

Vulnerability Description

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
GoogleChrome< 7.0.517.44
AppleItunes< 10.2
AppleSafari< 5.0.4
AppleIphone Os< 4.2
AppleMac Os X< 10.6.7
XmlsoftLibxml2< 2.7.8
DebianDebian Linux5.0
CanonicalUbuntu Linux6.06
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Eus6.3
RedhatEnterprise Linux Workstation6.0
OpensuseOpensuse11.1
SuseSuse Linux Enterprise Server10
ApacheOpenoffice>= 2.0.0, <= 2.4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4008?

CVE-2010-4008 is a vulnerability with a CVSS score of 4.3 (MEDIUM). libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressio...

How severe is CVE-2010-4008?

CVE-2010-4008 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4008?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Apple Itunes, Apple Safari, Apple Iphone Os, Apple Mac Os X.