Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3537

Опубликовано: 14 мая 2021
Источник: debian

Описание

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.9.10+dfsg-6.6package
libxml2fixed2.9.4+dfsg1-7+deb10u2busterpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libxml2/-/issues/243

  • https://gitlab.gnome.org/GNOME/libxml2/-/issues/244

  • https://gitlab.gnome.org/GNOME/libxml2/-/issues/245

  • https://gitlab.gnome.org/GNOME/libxml2/-/commit/babe75030c7f64a37826bb3342317134568bef61

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 4 лет назад

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
redhat
больше 4 лет назад

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

CVSS3: 5.9
nvd
больше 4 лет назад

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

CVSS3: 5.9
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.9
github
около 3 лет назад

Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing