CVE-2007-6284: Medium severity Mandrakesoft Mandrake Linux Corporate Server vulnerability

Published Dec 17, 2007
·
Updated

Description: There exists a denial of service problem in libxml's UTF-8 decoding functions. The xmlCurrentChar() function does not check UTF-8 correctness and certain multibyte combinations can cause the library to enter an infinite loop and hang, consuming system resources. It is strongly recommended to upgrade if your application accepts arbitrary xml user input.

Provided by: The issue was originally discovered at Google by Brad Fitzpatrick and further investigated by Peter Valchev and Will Drewry. Patch and debugging by Daniel Veillard (libxml).

Acknowledgements:

Red Hat would like to thank the Google Security Team for responsibly disclosing this issue.

Other sources

The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.

MITRE

Affected Software

38 affected components
Mandrakesoft Mandrake Linux Corporate Server=4.0
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Debian Debian Linux=3.1
Debian Debian Linux=3.1
Debian Debian Linux=3.1
redhat Fedora=7
Mandrakesoft Mandrake Linux=2007
redhat Fedora=8
Debian Debian Linux=4.0
Debian Debian Linux=3.1
Debian Debian Linux=3.1
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Mandrakesoft Mandrake Linux=2007.1
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Mandrakesoft Mandrake Linux Corporate Server=3.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Mandrakesoft Mandrake Linux Corporate Server=4.0
Mandrakesoft Mandrake Linux=2008.0
Mandrakesoft Mandrake Linux Corporate Server=3.0
Debian Debian Linux=3.1
Debian Debian Linux=3.1
Mandrakesoft Mandrake Linux=2007
Debian Debian Linux=3.1
Mandrakesoft Mandrake Linux=2007.1
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Mandrakesoft Mandrake Linux=2008.0
Debian Debian Linux=4.0
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Debian Debian Linux=3.1

Event History

Dec 17, 2007
Data Sourced
via Red Hat·09:25 AM
DescriptionSeverityAffected Software
Jan 12, 2008
CVE Published
02:46 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-6284?

CVE-2007-6284 is classified as a denial of service vulnerability that can cause the affected applications to hang indefinitely.

2

How do I fix CVE-2007-6284?

To mitigate CVE-2007-6284, it is recommended to update the libxml library to a patched version provided by your Linux distribution.

3

Which software is affected by CVE-2007-6284?

CVE-2007-6284 affects various versions of Debian Linux (3.1 and 4.0) and Mandrake Linux (2007 and 2008).

4

What causes the issue in CVE-2007-6284?

The issue in CVE-2007-6284 is due to the xmlCurrentChar() function in libxml not validating UTF-8 encoding correctly.

5

Can CVE-2007-6284 be exploited remotely?

Yes, CVE-2007-6284 can be exploited remotely if a malicious user sends specially crafted UTF-8 data to an application using the affected libxml library.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203