Описание
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
libxml2 | fixed | 2.9.3+dfsg1-1 | package | |
libxml2 | not-affected | jessie | package | |
libxml2 | not-affected | wheezy | package | |
libxml2 | not-affected | squeeze | package |
Примечания
https://bugzilla.gnome.org/show_bug.cgi?id=756372
Introduced by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/826bc320206f70fccd2941a77d363e95e8076898 (v2.9.2-rc1)
Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/8fb4a770075628d6441fb17a1e435100e2f3b1a2 (v2.9.3)
EPSS
Связанные уязвимости
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании или получить конфиденциальную информацию
EPSS