Description
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
Affected products
- sgi / propack2.3 – 2.3
- sgi / propack2.4 – 2.4
- xmlsoft / libxml1.8.17 – 1.8.17
- xmlsoft / libxml22.4.19 – 2.4.19
- xmlsoft / libxml22.4.23 – 2.4.23
- xmlsoft / libxml22.5.4 – 2.5.4
- xmlsoft / libxml22.5.10 – 2.5.10
- xmlsoft / libxml22.5.11 – 2.5.11
- xmlsoft / libxml22.6.0 – 2.6.0
- xmlsoft / libxml22.6.1 – 2.6.1
- xmlsoft / libxml22.6.2 – 2.6.2
- xmlsoft / libxml22.6.3 – 2.6.3
- xmlsoft / libxml22.6.4 – 2.6.4
- xmlsoft / libxml22.6.5 – 2.6.5
References
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11626
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A875
- MAILING_LISThttp://marc.info/?l=bugtraq&m=107851606605420&w=2
- MISChttp://rhn.redhat.com/errata/RHSA-2004-090.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/15302
- MISChttp://www.redhat.com/support/errata/RHSA-2004-091.html
- MISChttp://www.securityfocus.com/bid/9718
- VENDOR_ADVISORYhttp://www.debian.org/security/2004/dsa-455
- MISChttp://www.xmlsoft.org/news.html
- MISChttp://www.redhat.com/support/errata/RHSA-2004-650.html
- MISChttp://www.ciac.org/ciac/bulletins/o-086.shtml
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A833
- VENDOR_ADVISORYhttp://secunia.com/advisories/10958/
- VENDOR_ADVISORYhttp://www.novell.com/linux/security/advisories/2005_01_sr.html
- MISChttp://security.gentoo.org/glsa/glsa-200403-01.xml
- MISChttp://www.kb.cert.org/vuls/id/493966
- MAILING_LISThttp://marc.info/?l=bugtraq&m=107860178228804&w=2
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/15301