Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-40304

Опубликовано: 23 нояб. 2022
Источник: debian
EPSS Низкий

Описание

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.9.14+dfsg-1.1package

Примечания

  • Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b (v2.10.3)

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2335

EPSS

Процентиль: 21%
0.00067
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

CVSS3: 7.8
redhat
больше 2 лет назад

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

CVSS3: 7.8
nvd
больше 2 лет назад

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

CVSS3: 7.8
github
больше 2 лет назад

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

CVSS3: 8.2
fstec
почти 3 года назад

Уязвимость функции очистки объекта XML библиотеки анализа XML-документов libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00067
Низкий