Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-0841 | First vendor Publication | 2012-12-21 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0841 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14887 | |||
Oval ID: | oval:org.mitre.oval:def:14887 | ||
Title: | DSA-2417-1 libxml2 -- computational denial of service | ||
Description: | It was discovered that the internal hashing routine of libxml2, a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the hashing algorithm, it is possible to craft input that creates a large amount of collisions. As a result it is possible to perform denial of service attacks against applications using libxml2 functionality because of the computational overhead. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2417-1 CVE-2012-0841 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | libxml2 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:15454 | |||
Oval ID: | oval:org.mitre.oval:def:15454 | ||
Title: | USN-1376-1 -- libxml2 vulnerability | ||
Description: | libxml2: GNOME XML library libxml2 could be made to cause a denial of service by consuming excessive CPU resources. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1376-1 CVE-2012-0841 | Version: | 5 |
Platform(s): | Ubuntu 11.04 Ubuntu 11.10 Ubuntu 8.04 Ubuntu 10.04 Ubuntu 10.10 | Product(s): | libxml2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20110 | |||
Oval ID: | oval:org.mitre.oval:def:20110 | ||
Title: | VMware vSphere and vCOps updates to third party libraries | ||
Description: | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2012-0841 | Version: | 4 |
Platform(s): | VMWare ESX Server 4.1 VMWare ESX Server 4.0 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20976 | |||
Oval ID: | oval:org.mitre.oval:def:20976 | ||
Title: | RHSA-2012:0324: libxml2 security update (Moderate) | ||
Description: | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2012:0324-01 CESA-2012:0324 CVE-2012-0841 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 CentOS Linux 5 CentOS Linux 6 | Product(s): | libxml2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:23087 | |||
Oval ID: | oval:org.mitre.oval:def:23087 | ||
Title: | DEPRECATED: ELSA-2012:0324: libxml2 security update (Moderate) | ||
Description: | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012:0324-01 CVE-2012-0841 | Version: | 7 |
Platform(s): | Oracle Linux 5 Oracle Linux 6 | Product(s): | libxml2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:23733 | |||
Oval ID: | oval:org.mitre.oval:def:23733 | ||
Title: | ELSA-2012:0324: libxml2 security update (Moderate) | ||
Description: | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012:0324-01 CVE-2012-0841 | Version: | 6 |
Platform(s): | Oracle Linux 5 Oracle Linux 6 | Product(s): | libxml2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27873 | |||
Oval ID: | oval:org.mitre.oval:def:27873 | ||
Title: | DEPRECATED: ELSA-2012-0324 -- libxml2 security update (moderate) | ||
Description: | [2.7.6-4.0.1.el6_2.4] - Update doc/redhat.gif in tarball - Add libxml2-oracle-enterprise.patch and update logos in tarball [2.7.6-4.el6_2.4] - remove chunk in patch related to configure.in as it breaks rebuild - Resolves: rhbz#788845 [2.7.6-4.el6_2.3] - fix previous build to force compilation of randomization code - Resolves: rhbz#788845 [2.7.6-4.el6_2.2] - adds randomization to hash and dict structures CVE-2012-0841 - Resolves: rhbz#788845 | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012-0324 CVE-2012-0841 | Version: | 4 |
Platform(s): | Oracle Linux 5 Oracle Linux 6 | Product(s): | libxml2 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-10-03 | Name : Fedora Update for libxml2 FEDORA-2012-13824 File : nvt/gb_fedora_2012_13824_libxml2_fc16.nasl |
2012-09-27 | Name : Fedora Update for libxml2 FEDORA-2012-13820 File : nvt/gb_fedora_2012_13820_libxml2_fc17.nasl |
2012-08-31 | Name : VMSA-2012-0013 VMware vSphere and vCOps updates to third party libraries. File : nvt/gb_VMSA-2012-0013.nasl |
2012-07-30 | Name : CentOS Update for libxml2 CESA-2012:0324 centos6 File : nvt/gb_CESA-2012_0324_libxml2_centos6.nasl |
2012-07-13 | Name : VMSA-2012-0012 VMware ESXi update addresses several security issues. File : nvt/gb_VMSA-2012-0012.nasl |
2012-03-12 | Name : Debian Security Advisory DSA 2417-1 (libxml2) File : nvt/deb_2417_1.nasl |
2012-03-12 | Name : Gentoo Security Advisory GLSA 201203-04 (libxml2) File : nvt/glsa_201203_04.nasl |
2012-03-07 | Name : Ubuntu Update for libxml2 USN-1376-1 File : nvt/gb_ubuntu_USN_1376_1.nasl |
2012-02-27 | Name : RedHat Update for libxml2 RHSA-2012:0324-01 File : nvt/gb_RHSA-2012_0324-01_libxml2.nasl |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2012-09-27 | IAVM : 2012-A-0153 - Multiple Vulnerabilities in VMware ESX 4.0 and ESXi 4.0 Severity : Category I - VMSKEY : V0033884 |
2012-09-13 | IAVM : 2012-B-0086 - VMware vCenter Operations Arbitrary File Overwrite Vulnerability Severity : Category I - VMSKEY : V0033791 |
2012-09-13 | IAVM : 2012-A-0146 - Multiple Vulnerabilities in VMware vCenter Update Manager 4.1 Severity : Category I - VMSKEY : V0033792 |
2012-09-13 | IAVM : 2012-A-0147 - Multiple Vulnerabilities in VMware vCenter Server 4.1 Severity : Category I - VMSKEY : V0033793 |
2012-09-13 | IAVM : 2012-A-0148 - Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity : Category I - VMSKEY : V0033794 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-02-29 | Name : The remote VMware ESX / ESXi host is missing a security-related patch. File : vmware_VMSA-2012-0013_remote.nasl - Type : ACT_GATHER_INFO |
2016-02-29 | Name : The remote VMware ESX / ESXi host is missing a security-related patch. File : vmware_VMSA-2012-0012_remote.nasl - Type : ACT_GATHER_INFO |
2015-05-20 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2013-1627-1.nasl - Type : ACT_GATHER_INFO |
2015-01-23 | Name : The remote device is missing a vendor-supplied security patch. File : juniper_jsa10669.nasl - Type : ACT_GATHER_INFO |
2015-01-19 | Name : The remote Solaris system is missing a security patch for third-party software. File : solaris11_libxml2_20121120.nasl - Type : ACT_GATHER_INFO |
2014-11-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2012-0422.nasl - Type : ACT_GATHER_INFO |
2014-11-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2012-1324.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_4_libxml2-120224.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2012-179.nasl - Type : ACT_GATHER_INFO |
2014-01-23 | Name : The remote host contains an application that has multiple vulnerabilities. File : itunes_11_1_4.nasl - Type : ACT_GATHER_INFO |
2014-01-23 | Name : The remote host contains a multimedia application that has multiple vulnerabi... File : itunes_11_1_4_banner.nasl - Type : ACT_GATHER_INFO |
2013-11-13 | Name : The remote VMware ESXi 5.0 host is affected by multiple vulnerabilities. File : vmware_esxi_5_0_build_912577_remote.nasl - Type : ACT_GATHER_INFO |
2013-11-13 | Name : The remote VMware ESXi 5.0 host is affected by multiple security vulnerabilit... File : vmware_esxi_5_0_build_764879_remote.nasl - Type : ACT_GATHER_INFO |
2013-10-24 | Name : The remote host contains an application that has multiple vulnerabilities. File : itunes_11_1_2.nasl - Type : ACT_GATHER_INFO |
2013-10-24 | Name : The remote host contains a multimedia application that has multiple vulnerabi... File : itunes_11_1_2_banner.nasl - Type : ACT_GATHER_INFO |
2013-10-01 | Name : The remote device is affected by multiple vulnerabilities. File : appletv_6_0.nasl - Type : ACT_GATHER_INFO |
2013-09-04 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2012-52.nasl - Type : ACT_GATHER_INFO |
2013-07-29 | Name : The remote host has a virtualization appliance installed that is affected by ... File : vcenter_operations_manager_vmsa_2012-0013.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2012-0324.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2013-0217.nasl - Type : ACT_GATHER_INFO |
2013-06-17 | Name : The remote host has an update manager installed that is affected by multiple ... File : vmware_vcenter_update_mgr_vmsa-2012-0013.nasl - Type : ACT_GATHER_INFO |
2013-06-05 | Name : The remote host has a virtualization management application installed that is... File : vmware_vcenter_vmsa-2012-0013.nasl - Type : ACT_GATHER_INFO |
2013-02-04 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20130131_mingw32_libxml2_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2013-02-01 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0217.nasl - Type : ACT_GATHER_INFO |
2013-02-01 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2013-0217.nasl - Type : ACT_GATHER_INFO |
2013-01-25 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_libxml2-120223.nasl - Type : ACT_GATHER_INFO |
2012-09-27 | Name : The remote Fedora host is missing a security update. File : fedora_2012-13824.nasl - Type : ACT_GATHER_INFO |
2012-09-27 | Name : The remote Fedora host is missing a security update. File : fedora_2012-13820.nasl - Type : ACT_GATHER_INFO |
2012-08-31 | Name : The remote VMware ESXi / ESX host is missing one or more security-related pat... File : vmware_VMSA-2012-0013.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20120221_libxml2_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-07-13 | Name : The remote VMware ESXi host is missing a security-related patch. File : vmware_VMSA-2012-0012.nasl - Type : ACT_GATHER_INFO |
2012-05-17 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_libxml2-7997.nasl - Type : ACT_GATHER_INFO |
2012-03-06 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201203-04.nasl - Type : ACT_GATHER_INFO |
2012-02-28 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1376-1.nasl - Type : ACT_GATHER_INFO |
2012-02-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2417.nasl - Type : ACT_GATHER_INFO |
2012-02-23 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2012-0324.nasl - Type : ACT_GATHER_INFO |
2012-02-22 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2012-0324.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 22:58:45 |
|
2024-11-28 12:28:57 |
|
2024-08-02 12:19:06 |
|
2024-08-02 01:05:39 |
|
2024-02-02 01:18:33 |
|
2024-02-01 12:05:30 |
|
2023-09-05 12:17:30 |
|
2023-09-05 01:05:23 |
|
2023-09-02 12:17:31 |
|
2023-09-02 01:05:28 |
|
2023-08-12 12:21:16 |
|
2023-08-12 01:05:29 |
|
2023-08-11 12:17:38 |
|
2023-08-11 01:05:39 |
|
2023-08-06 12:16:56 |
|
2023-08-06 01:05:29 |
|
2023-08-04 12:17:00 |
|
2023-08-04 01:05:32 |
|
2023-07-14 12:16:59 |
|
2023-07-14 01:05:27 |
|
2023-03-29 01:18:56 |
|
2023-03-28 12:05:35 |
|
2023-02-13 05:28:29 |
|
2023-02-02 17:28:11 |
|
2022-10-11 12:15:10 |
|
2022-10-11 01:05:11 |
|
2021-05-23 12:09:28 |
|
2021-05-04 12:19:19 |
|
2021-04-22 01:23:02 |
|
2020-05-23 01:48:13 |
|
2020-05-23 00:33:00 |
|
2019-09-27 12:04:41 |
|
2019-07-03 01:04:11 |
|
2018-11-15 12:04:17 |
|
2018-04-07 12:04:28 |
|
2016-04-26 21:33:39 |
|
2016-03-01 13:26:32 |
|
2015-05-21 13:29:25 |
|
2015-01-24 13:23:34 |
|
2015-01-21 13:25:16 |
|
2014-11-18 13:26:00 |
|
2014-11-08 13:30:02 |
|
2014-06-14 13:32:24 |
|
2014-02-17 11:08:24 |
|
2014-01-28 13:19:10 |
|
2014-01-24 13:19:04 |
|
2013-11-11 12:39:48 |
|
2013-10-31 13:19:13 |
|
2013-10-11 13:23:37 |
|
2013-09-27 13:21:04 |
|
2013-09-27 00:19:41 |
|
2013-09-20 13:19:58 |
|
2013-05-30 13:23:06 |
|
2013-05-10 22:34:06 |
|
2013-04-18 13:19:48 |
|
2013-02-07 13:20:00 |
|
2012-12-28 00:18:41 |
|
2012-12-21 17:23:20 |
|
2012-12-21 13:20:19 |
|