Libxml2 contains an overflow condition in the 'xmlStringLenDecodeEntities()' function [parser.c] that is triggered when copying entities. With a specially crafted request, a remote attacker can cause a heap-based buffer overflow to cause a denial of service or potentially execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
It has been reported that this issue has been fixed. Upgrade to version 2.8.0-rc1, or higher, to address this vulnerability.
Upgrade to Google Chrome version 16.0.912.75 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.