HTTP: libxml2 XML File Processing Long Entity Name Buffer Overflow

This signature detects attempts to exploit a known vulnerability in libxml2 XML library. A successful attack could allow the attacker to execute arbitrary code on the targeted system. Failed exploit attempts could result in a denial of service condition.

Extended Description

The 'libxml' library is prone to a heap-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data. An attacker can exploit this issue to execute arbitrary within the context of an application using the affected library. Failed exploit attempts will result in a denial-of-service vulnerability.

Affected Products

Apple iphone,Avaya proactive_contact

References

BugTraq: 31126

CVE: CVE-2008-3529

Short Name
HTTP:STC:DL:LIBXML2-ENTRY-NAME
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2008-3529 Entity File Long Name Overflow Processing XML bid:31126 libxml2
Release Date
10/13/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Red_hat

Suse

Apple

Gentoo

Sun

Rpath

Avaya

Ubuntu

Mandriva

Nortel_networks

Xmlsoft

Debian

CVSS Score

10.0

Found a potential security threat?