CVE-2012-2893
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2893
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1.1.26-14 |
| debian | bullseye | fixed | 1.1.26-14 |
| debian | forky | fixed | 1.1.26-14 |
| debian | sid | fixed | 1.1.26-14 |
| debian | trixie | fixed | 1.1.26-14 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| chrome | {"endIncluding":"22.0.1229.78"} | | |
| chrome | 22.0.1229.0 | | |
| chrome | 22.0.1229.1 | | |
| chrome | 22.0.1229.2 | | |
| chrome | 22.0.1229.3 | | |
| chrome | 22.0.1229.4 | | |
| chrome | 22.0.1229.6 | | |
| chrome | 22.0.1229.7 | | |
| chrome | 22.0.1229.8 | | |
| chrome | 22.0.1229.9 | | |
| chrome | 22.0.1229.10 | | |
| chrome | 22.0.1229.11 | | |
| chrome | 22.0.1229.12 | | |
| chrome | 22.0.1229.14 | | |
| chrome | 22.0.1229.16 | | |
| chrome | 22.0.1229.17 | | |
| chrome | 22.0.1229.18 | | |
| chrome | 22.0.1229.20 | | |
| chrome | 22.0.1229.21 | | |
| chrome | 22.0.1229.22 | | |
| chrome | 22.0.1229.23 | | |
| chrome | 22.0.1229.24 | | |
| chrome | 22.0.1229.25 | | |
| chrome | 22.0.1229.26 | | |
| chrome | 22.0.1229.27 | | |
| chrome | 22.0.1229.28 | | |
| chrome | 22.0.1229.29 | | |
| chrome | 22.0.1229.31 | | |
| chrome | 22.0.1229.32 | | |
| chrome | 22.0.1229.33 | | |
| chrome | 22.0.1229.35 | | |
| chrome | 22.0.1229.36 | | |
| chrome | 22.0.1229.37 | | |
| chrome | 22.0.1229.39 | | |
| chrome | 22.0.1229.48 | | |
| chrome | 22.0.1229.49 | | |
| chrome | 22.0.1229.50 | | |
| chrome | 22.0.1229.51 | | |
| chrome | 22.0.1229.52 | | |
| chrome | 22.0.1229.53 | | |
| chrome | 22.0.1229.54 | | |
| chrome | 22.0.1229.55 | | |
| chrome | 22.0.1229.56 | | |
| chrome | 22.0.1229.57 | | |
| chrome | 22.0.1229.58 | | |
| chrome | 22.0.1229.59 | | |
| chrome | 22.0.1229.60 | | |
| chrome | 22.0.1229.62 | | |
| chrome | 22.0.1229.63 | | |
| chrome | 22.0.1229.64 | | |
| chrome | 22.0.1229.65 | | |
| chrome | 22.0.1229.67 | | |
| chrome | 22.0.1229.76 | |
References
- http://git.chromium.org/gitweb/?p=chromium.git%3Ba=commit%3Bh=9a5da8e7d4b6f3454614b0331a51bf29c966f556
- http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html
- http://secunia.com/advisories/50838
- http://www.debian.org/security/2012/dsa-2555
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:164
- https://chromiumcodereview.appspot.com/10919019
- https://code.google.com/p/chromium/issues/detail?id=144799
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15714
- https://src.chromium.org/viewvc/chrome?view=rev&revision=154331
- https://security-tracker.debian.org/tracker/CVE-2012-2893
CWEs
CWE-399
Verify integrity in audit chain (admin only). AS-IS.