parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
AV:N/AC:L/Au:N/C:N/I:N/A:P
Vendors | Products |
---|---|
Xmlsoft |
|
|
Configuration 1 [-]
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Chrome
Published: 2013-07-10T10:00:00
Updated: 2018-10-09T18:57:01
Reserved: 2013-04-11T00:00:00
Link: CVE-2013-2877
JSON object: View
NVD Information
Status : Modified
Published: 2013-07-10T10:55:02.260
Modified: 2023-11-07T02:15:25.030
Link: CVE-2013-2877
JSON object: View
Redhat Information
No data.
CWE