RULE(RULE ID:311232)

Rule General Information
Release Date: 2013-05-20
Rule Name: Multiple Products libxml2 XML file processing long entity name Buffer Overflow Vulnerability -2 (CVE-2008-3529)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
Impact: Remote code execution
Affected OS: Others, Mac OS, Other Unix, Linux
Reference: SecurityFocusBID:31126
ExploitDB:8798
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
Solutions
Update vendor's patch.