vendor:
Libxml2
by:
Google Security Research
7,5
CVSS
HIGH
Heap-Based Out-of-Bounds Memory Read
787
CWE
Product Name: Libxml2
Affected Version From: 2.9.3
Affected Version To: 2.9.3
Patch Exists: YES
Related CWE: N/A
CPE: a:libxml:libxml2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Heap-Based Out-of-Bounds Memory Read in Libxml2
The vulnerability is a heap-based out-of-bounds memory read in libxml2, which is a library providing support to read, modify and write XML and HTML files. The vulnerability can be triggered by feeding a malformed file to xmllint. The crash due to the vulnerability can be observed in an ASAN build of the latest stable libxml2 (2.9.3, released 4 days ago).
Mitigation:
Upgrade to the latest version of libxml2 (2.9.3) to mitigate the vulnerability.