Upstream information
Description
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entries: 791234, 793334, 795039, 804033 SUSE Security Advisories:- SUSE-SU-2012:1636-1, published Wed, 12 Dec 2012 17:09:09 +0100 (CET)
- openSUSE-SU-2012:1637-1, published Wed, 12 Dec 2012 17:09:13 +0100 (CET)
- openSUSE-SU-2012:1647-1, published Mon, 17 Dec 2012 12:08:33 +0100 (CET)
- openSUSE-SU-2013:0178-1, published Wed, 23 Jan 2013 14:07:38 +0100 (CET)
