CVE-2017-15412: Use After Free
A use-after-free flaw was found in the libxml2 library. An attacker could use this flaw to cause an application linked against libxml2 to crash when parsing a specially crafted XML file.
Other sources
An use after free flaw was found in the libXML component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=727039
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
— Red Hat
libxml2. A use after free issue was addressed with improved memory management.
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4155
- CVE-2018-4142
- CVE-2018-4167
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4185
- CVE-2017-15412
- CVE-2018-4166
- CVE-2018-4157
- CVE-2018-4144
- CVE-2018-4115
- CVE-2018-4113
- CVE-2018-4146
- CVE-2018-4101
- CVE-2018-4114
- CVE-2018-4118
- CVE-2018-4119
- CVE-2018-4120
- CVE-2018-4121
- CVE-2018-4122
- CVE-2018-4125
- CVE-2018-4127
- CVE-2018-4128
- CVE-2018-4129
- CVE-2018-4130
- CVE-2018-4161
- CVE-2018-4162
- CVE-2018-4163
- CVE-2018-4165
- CVE-2018-4207
- CVE-2018-4208
- CVE-2018-4209
- CVE-2018-4210
- CVE-2018-4212
- CVE-2018-4213
- CVE-2018-4145
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4158
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4139
- CVE-2018-4175
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4298
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4106
- CVE-2018-4131
- CVE-2018-4390
- CVE-2018-4391
- CVE-2018-4117
- CVE-2018-4177
- CVE-2018-4123
- CVE-2018-4168
- CVE-2018-4172
- CVE-2018-4134
- CVE-2018-4137
- CVE-2018-4149
- CVE-2018-4140
- CVE-2018-4148
- CVE-2018-4110
Frequently Asked Questions
What is CVE-2017-15412?
CVE-2017-15412 is a use after free vulnerability in libxml2 before version 2.9.5.
How does CVE-2017-15412 affect Google Chrome?
CVE-2017-15412 affects Google Chrome versions prior to 63.0.3239.84.
What is the severity of CVE-2017-15412?
CVE-2017-15412 has a severity rating of 8.8 (High).
How can I fix CVE-2017-15412 in Google Chrome?
To fix CVE-2017-15412 in Google Chrome, update to version 63.0.3239.84 or later.
Where can I find more information about CVE-2017-15412?
You can find more information about CVE-2017-15412 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-15412), [Red Hat Security Advisory 2017:3401](https://access.redhat.com/errata/RHSA-2017:3401), [Red Hat Security Advisory 2018:0287](https://access.redhat.com/errata/RHSA-2018:0287).