HIGH · 7.5

CVE-2010-4494

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have uns...

Vulnerability Description

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
GoogleChrome< 8.0.552.215
XmlsoftLibxml2<= 2.7.8
AppleItunes< 10.2
AppleSafari< 5.0.4
AppleIphone Os< 4.3.0
AppleMac Os X< 10.6.7
OpensuseOpensuse11.2
SuseSuse Linux Enterprise Server11
FedoraprojectFedora14
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.3
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Workstation6.0
DebianDebian Linux5.0
HpInsight Control Server DeploymentAll versions
HpRapid Deployment PackAll versions
ApacheOpenoffice>= 2.1.0, <= 2.4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4494?

CVE-2010-4494 is a vulnerability with a CVSS score of 7.5 (HIGH). Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have uns...

How severe is CVE-2010-4494?

CVE-2010-4494 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4494?

Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Xmlsoft Libxml2, Apple Itunes, Apple Safari, Apple Iphone Os.