Novell Home


Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-1969 at MITRE


Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.

NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Note from the SUSE Security Team

This security issue only affects libxml 2.9.0 or newer, so libxml2 versions on SUSE Linux Enterprise 11 (2.7.6) or older products are not affected.

Novell Bugzilla entry: 815665

SUSE Security Advisories:

© 2014 Novell