SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  Libxml2 Vendors:  xmlsoft.org
Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1009222
SecurityTracker URL:  http://securitytracker.com/id?1009222
CVE Reference:  CAN-2004-0110   (Links to External Site)
Date:  Feb 26 2004
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): prior to 2.6.6
Description:  A buffer overflow vulnerability was reported in Libxml2. A remote user may be able to execute arbitrary code on an application that uses Libxml2.

It is reported that there is an overflow in libxml2 that can be triggered when parsing remote resources via FTP or HTTP. A long URL can trigger the overflow, the report said.

The flaw reportedly resides in 'nanoftp.c' and 'nanohttp.c'

Yuuichi Teranishi is credited with discovering the flaw.

Impact:  A remote user may be able to cause a target application that uses Libxml2 to execute arbitrary code with the privileges of the target application. The specific impact depends on the application using Libxml2.
Solution:  The vendor has released a fixed version (2.6.6 and later), available at:

http://www.xmlsoft.org/downloads.html

Vendor URL:  www.xmlsoft.org/index.html (Links to External Site)
Cause:  Boundary error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Feb 26 2004 (Red Hat Issues Fix for RH Linux) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (bugzilla@redhat.com)
This fix for Red Hat Linux 9 is now obsolete, having been replaced by a new fix as described in Red Hat security advisory RHSA-2004:091-02.
Feb 26 2004 (Red Hat Issues Fix for RH Enterprise Linux) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 2.1, 3.
Mar 3 2004 (Red Hat Issues Revised Fix for RH Linux) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (bugzilla@redhat.com)
Red Hat has released a revised fix for Red Hat Linux 9 to correct the previous, incomplete fix.
Mar 4 2004 (Mandrake Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a fix.
Mar 4 2004 (Debian Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (joey@infodrom.org (Martin Schulze))
Debian has released a fix.
Mar 8 2004 (Trustix Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Trustix Security Advisor <tsl@trustix.org>)
Trustix has released a fix.
Mar 8 2004 (Gentoo Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Tim Yamin <plasmaroo@gentoo.org>)
Gentoo has released a fix.
Apr 1 2004 (Conectiva Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Conectiva Updates <secure@conectiva.com.br>)
Conectiva has released a fix.
Apr 6 2004 (Apple Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Apple Product Security <product-security@apple.com>)
Apple has released a fix for Mac OS X.
Oct 4 2004 (Fedora Issues Fix for RH Linux) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (Marc Deslauriers <marcdeslauriers@videotron.ca>)
Fedora has released a fix for Red Hat Linux 7.3
Dec 16 2004 (Red Hat Issues Fix) Libxml2 URL Parsing Buffer Overflow May Let Remote Users Execute Arbitrary Code   (bugzilla@redhat.com)
Red Hat has released a fix.



 Source Message Contents

Date:  Thu, 26 Feb 2004 09:26:21 -0500
Subject:  CAN-2004-0110

 

CVE: CAN-2004-0110

Red Hat reported that there is an overflow in libxml2 that can be triggered when parsing 
remote resources via FTP or HTTP.  A long URL can trigger the overflow.

Yuuichi Teranishi is credited with discovering the flaw.

Versions prior to 2.6.6 are reportedly affected.


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC