CVE-2011-2821

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.

References

http://code.google.com/p/chromium/issues/detail?id=89402

http://googlechromereleases.blogspot.com/2011/08/stable-channel-update_22.html

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041

http://lists.apple.com/archives/security-announce/2012/May/msg00001.html

http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html

http://rhn.redhat.com/errata/RHSA-2013-0217.html

http://support.apple.com/kb/HT5281

http://support.apple.com/kb/HT5503

http://www.debian.org/security/2012/dsa-2394

http://www.mandriva.com/security/advisories?name=MDVSA-2011:145

http://www.redhat.com/support/errata/RHSA-2011-1749.html

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13840

Details

Source: MITRE

Published: 2011-08-29

Updated: 2020-05-19

Type: CWE-415

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (28 total)

IDNameProductFamilySeverity
80688Oracle Solaris Third-Party Patch Update : libxml2 (cve_2011_0216_denial_of)NessusSolaris Local Security Checks
high
75936openSUSE Security Update : libxml2 (openSUSE-SU-2012:0073-1)NessusSuSE Local Security Checks
high
75635openSUSE Security Update : libxml2 (openSUSE-SU-2012:0073-1)NessusSuSE Local Security Checks
high
68721Oracle Linux 6 : mingw32-libxml2 (ELSA-2013-0217)NessusOracle Linux Local Security Checks
high
64425Scientific Linux Security Update : mingw32-libxml2 on SL6.x (x86_64) (20130131)NessusScientific Linux Local Security Checks
high
64391RHEL 6 : mingw32-libxml2 (RHSA-2013:0217)NessusRed Hat Local Security Checks
high
64384CentOS 6 : mingw32-libxml2 (CESA-2013:0217)NessusCentOS Local Security Checks
high
62357Apple TV < 5.1 Multiple VulnerabilitiesNessusGain a shell remotely
high
62324Fedora 16 : libxml2-2.7.8-8.fc16 (2012-13824)NessusFedora Local Security Checks
high
62323Fedora 17 : libxml2-2.7.8-9.fc17 (2012-13820)NessusFedora Local Security Checks
high
6589Apple iOS < 6.0 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
high
62242Apple iOS < 6.0 Multiple VulnerabilitiesNessusMobile Devices
critical
61192Scientific Linux Security Update : libxml2 on SL6.x i386/x86_64NessusScientific Linux Local Security Checks
critical
59966VMSA-2012-0012 : VMware ESXi update to third-party libraryNessusVMware ESX Local Security Checks
high
59851HP System Management Homepage < 7.1.1 Multiple VulnerabilitiesNessusWeb Servers
critical
6482Mac OS X 10.7 < 10.7.4 Multiple VulnerabilitiesNessus Network MonitorGeneric
critical
59067Mac OS X Multiple Vulnerabilities (Security Update 2012-002) (BEAST)NessusMacOS X Local Security Checks
critical
59066Mac OS X 10.7.x < 10.7.4 Multiple Vulnerabilities (BEAST)NessusMacOS X Local Security Checks
critical
57702Debian DSA-2394-1 : libxml2 - several vulnerabilitiesNessusDebian Local Security Checks
high
57615Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : libxml2 vulnerabilities (USN-1334-1)NessusUbuntu Local Security Checks
high
57531SuSE 11.1 Security Update : libxml2 (SAT Patch Number 5489)NessusSuSE Local Security Checks
high
57022RHEL 6 : libxml2 (RHSA-2011:1749)NessusRed Hat Local Security Checks
critical
56660GLSA-201110-26 : libxml2: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
56429Mandriva Linux Security Advisory : libxml2 (MDVSA-2011:145)NessusMandriva Local Security Checks
high
800914Google Chrome < 13.0.782.215 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6016Google Chrome < 13.0.782.215 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
55959Google Chrome < 13.0.782.215 Multiple VulnerabilitiesNessusWindows
high
51069FreeBSD : chromium -- multiple vulnerabilities (6887828f-0229-11e0-b84d-00262d5ed8ee)NessusFreeBSD Local Security Checks
critical